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Abstract 

This is the third installment in a series of papers on algebraic set theory. 
In it, we develop a uniform approach to sheaf models of constructive set 
theories based on ideas from categorical logic. The key notion is that of 
a "predicative category with small maps" which axiomatises the idea of 
a category of classes and class morphisms, together with a selected class 
of maps whose fibres are sets (in some axiomatic set theory). The main 
result of the present paper is that such predicative categories with small 
maps are stable under internal sheaves. We discuss the sheaf models of 
constructive set theory this leads to, as well as ideas for future workQ 

1 Introduction 

This is the third in a series of papers on algebraic set theory, the aim of which is 
to develop a categorical semantics for constructive set theories, including pred- 
icative ones, based on the notion of a "predicative category with small maps" H 
In the first paper in this series [9] we discussed how these predicative categories 
with small maps provide a sound and complete semantics for constructive set 
theory. In the second one [12] , we explained how realizability extensions of such 
predicative categories with small maps can be constructed. The purpose of the 
present paper is to do the same for sheaf-theoretic extensions. This program 
was summarised in [11] , where we announced the results that we will present 
and prove here. 
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For the convenience of the reader, and also to allow a comparison with the 
work by other researchers, we outline the main features of our approach. As 
said, the central concept in our theory is that of a predicative category with 
small maps. It axiomatises the idea of a category whose objects are classes and 
whose morphisms are functions between classes, and which is moreover equipped 
with a designated class of maps. The maps in the designated class are called 
small, and the intuitive idea is that the fibres of these maps are sets (in a certain 
axiomatic set theory). Such categories are in many ways like toposes, and to a 
large extent the purpose of our series of papers is to develop a topos theory for 
these categories. Indeed, like toposes, predicative categories with small maps 
turn out to be closed under realizability and sheaves. 

On the other hand, where toposes can be seen as models of a typed version of 
(constructive) higher-order arithmetic, predicative categories with small maps 
provide models of (constructive) set theories. Furthermore, the notion of a 
predicative category with small maps is proof-theoretically rather weak: this 
allows us to model set theories which are proof-theoretically weaker than higher- 
order arithmetic, such as Aczel's set theory CZF (see [I]). But at the same time, 
the notion of a predicative category with small maps can also be strengthened, 
so that it leads to models of set theories proof-theoretically stronger than higher- 
order arithmetic, like IZF. The reason for this is that one can impose additional 
axioms on the class of small maps. This added flexibility is an important feature 
of algebraic set theory. 

A central result in algebraic set theory says that the semantics provided by 
predicative categories with small maps is complete. More precisely, every pred- 
icative category with small maps contains an object ( "the initial ZF-algebra" in 
the terminology of [23] . or "the initial "Pg-algebra" in the terminology of 
which carries the structure of a model of set theory. Which set-theoretic ax- 
ioms hold in this model depends on the properties of the class of small maps 
and on the logic of the underlying category: in different situations, this initial 
ZF-algebra can be a model of CZF, of IZF, or of ordinary ZF. (The axioms 
of the constructive set theores CZF and IZF are recalled in Section 2 below.) 
The completeness referred to above results from the fact that from the syntax of 
CZF (or (I)ZF ), we can build a predicative category with small maps with the 
property that in the initial ZF-algebra in this category, precisely those sentences 
are valid which are derivable from the axiom of CZF (see [9]). (Completeness 
theorems of this kind go back to [31j |6]. One should also mention that one 
can obtain a predicative category with small maps from the syntax of Martin- 
Lof type theory: Aczel's interpretation of CZF in Martin-L6f type theory goes 
precisely via the initial ZF-algebra in this category. In fact, our proof of the 
existence of the initial ZF-algebra in any predicative category with small maps 
in [5] was modelled on Aczel's interpretation, as it was in 29 ..) 

In algebraic set theory we approach the construction of realizability cate- 

3 Appendix A in 24 contains a proof of the fact that both these terms refer to the same 
object. In the sequel we will use these terms interchangably. 
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gories and of categories of sheaves in a topos-theoretic spirit; that is, we regard 
these realizability and sheaf constructions as closure properties of predicative 
categories with small maps. For realizability this means that starting from any 
predicative category with small maps (£,<S) one can build a predicative real- 
izability category with small maps (£ffe,£ffs) over it- Inside both of these 
categories, we have models of constructive set theory (CZF say), as shown in 
the following picture. Here, the vertical arrows are two instances of the same 
construction of the initial ZF-algebra, applied to different predicative categories 
with small maps: 

(£, S) > (Sff E , Sff s ) 



model of CZF > realizability model of CZF 

Traditional treatments of realizability either regard it as a model-theoretic 
construction (which would correspond to the lower edge of the diagram), or as 
a proof-theoretic interpretation (defining a realizability model of CZF inside 
CZF, as in [30], for instance): the latter would correspond to the left-hand 
vertical arrow in the special case where £ is the syntactic category associated to 
CZF. So in a way our treatment captures both constructions in a uniform way. 

That realizability is indeed a closure property of predicative categories with 
small maps was the principal result of (9] . The main result of the present paper 
is that the same is true for sheaves, leading to an analogous diagram: 

(£, S) ► (Sh £ , Sh 5 ) 



model of CZF > sheaf model of CZF 

The main technical difficulty in showing that predicative categories with small 
maps are closed under sheaves lies in showing that the axioms concerning in- 
ductive types (W-types) and an axiom called "fullness" (needed to model the 
subset collection axiom of CZF) are inherited by sheaf models. The proofs of 
these facts are quite long and involved, and take up a large part of this paper 
(the situation for realizability was very similar) . 

To summarise, in our approach there is one uniform construction of a model 
out of a predicative category with small maps (£,S), which one can apply to 
different kinds of such categories, constructed using syntax, using realizability, 
using sheaves, or any iteration or combination of these techniques. 

We proceed to compare our results with those of other authors. Early work 
on categorical semantics of set theory (for example, [16] and [15]) was concerned 
with sheaf and realizability toposes defined over Sets. The same applies to the 
book which introduced algebraic set theory [24 . In particular, to the best of 
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our knowledge, before our work a systematic account was lacking of iterations 
and combinations of realizability and sheaf interpretations. In addition these 
earlier papers were concerned exclusively with impredicative set theories, such 
as ZF or IZF: the only exception seems to have been an early paper [2T] by 
Grayson, treating models of predicative set theory in the context of what would 
now be called formal topology. 

The first paper extending the methods of algebraic set theory to predicative 
systems was [53]. The authors of this paper showed how categorical models of 
Martin-L6f type theory (with universes) lead to models of CZF extended with 
a choice principle, which they dubbed the Axiom of Multiple Choice (AMC). 
They established how such categorical models of type theory are closed under 
sheaves, hence leading to sheaf models of a strengthening of CZF. They did 
not develop a semantics for CZF per se and relied on a technical notion of a 
collection site, which we manage to avoid here (moreover, there was a mistake 
in their treatment of W-types of sheaves; we correct this in Section 4.4 below, 
see also [TU]). 

Two accounts of presheaf models in the context of algebraic set theory have 
been written by Gambino [T5] and Warren [33]. In [T8] Gambino shows how 
an earlier (unpublished) construction of a model of constructive set theory by 
Dana Scott can be regarded as an initial ZF-algebra in a category of presheaves, 
and that one can perform the construction in a predicative metatheory as well. 
Warren shows in [34] that many of the axioms that we will discuss are inherited 
by categories of coalgebras for a Cartesian comonad, a construction which in- 
cludes presheaf models as a special case. But note that neither of these authors 
discusses the technically complicated axioms concerning W-types and fullness, 
as we will do in Sections 3 and 4 below. 

In his PhD thesis [17] , Gambino gave a systematic account of Heyting- valued 
models for CZF (see also [H]). This work was in the context of formal topology 
(essentially, sites whose underlying categories are posets). He has subsequently 
worked on generalising this to arbitrary sites and on putting this in the context 
of algebraic set theory. In [3D] , he took the first step in constructing the sheafifi- 
cation functor and in [7j, written together with Awodey, Lumsdaine and Warren, 
he checks that the basic axioms for small maps are inherited by categories of 
sheaves in the general setting of sheaves for a Lawvere-Tierney topology. We 
will extend these results by proving that for sites which have a presentation (for 
a definition, see Definition 14. II below) . the axioms for W-types and for fullness 
are stable under taking sheaf extensions. Note that for proof-theoretic reasons, 
fullness cannot be stable under taking more general kinds of sheaves such as 
those for a site which does not have a presentation, or for a Lawvere-Tierney 
topology. The point is that CZF extended with the Law of Excluded Middle 
gives ZF, a much stronger system proof-theoretically, and therefore a double- 
negation interpretation of CZF in itself must fail. The culprit turns out to be 
the fullness axiom, which can therefore not be stable under taking sheaves for 
the double- negation topology or sheaves for an arbitrary site (see [19] and |21j). 
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We conclude this introduction by outlining the organisation of our paper. 
In Section 2 we recall the main definitions from [IT] [9] . We will introduce the 
axioms for a class of small maps necessary to obtain models of CZF and IZF. 
Among these necessary axioms, we will discuss the fullness axiom, the axioms 
concerning W-types and the axiom of multiple choice in detail, as these are the 
most complicated technically and our main results, which we formulate precisely 
in Section 2.5, are concerned with these axioms. 

In Section 3 we show that predicative categories with small maps are closed 
under presheaves and that all the axioms that we have listed in Section 2 are 
inherited by such presheaf models. An important part of our treatment is that 
we distinguish between two classes of small maps: the "pointwise" and "locally" 
small ones. It turns out that for certain axioms it is easier to show that they 
are inherited by pointwise small maps while for other axioms it is easier to show 
that they are inherited by locally small maps, and therefore it is an important 
result that these classes of maps coincide. 

We follow a similar strategy in Section 4, where we discuss sheaves: we again 
distinguish between two classes of maps, where for some axioms it is easier to 
use one definition, while for other axioms it turns out to be easier to use the 
other. To show that these two classes coincide we use the fullness axiom and 
assume that the site has a presentation^ This section also contains our main 
technical results: that sheaf models inherit the fullness axiom, as well as the 
axioms concerning W-typesi Strictly speaking our results for presheaves in 
Section 3 are special cases of our results in Section 4. We believe, however, 
that it is useful to give direct proofs of the results for presheaves, and in many 
cases it is helpful to see how the proof goes in the (easier) presheaf case before 
embarking on the more involved proofs in the sheaf case. 

Finally, in Section 5 we give explicit descriptions of the sheaf models of 
constructive set theory our results lead to. We also point out the connection to 
forcing for classical set theories. 

This will complete our program for developing an abstract semantics of con- 
structive set theory, in particular of Aczel's CZF, as outlined [TTJ. As a result 
topos-theoretic insights and categorical methods can now be used in the study 
of constructive set theories. For instance, one can obtain consistency and in- 
dependence results using sheaf and realizability models or by a combination of 
these interpretations. In future work, we will use sheaf-theoretic methods to 
show that the fan rule as well as certain continuity rules are derived rules for 
CZF and related theories [T3] . 

The main results of this paper were presented by the second author in a 

4 In | X 11 we claimed that (instead of fullness) the exponentiation axiom would suffice to 
establish this result, but that might not be correct. 

5 One subtlety arises when we try to show that an axiom saying that certain inductives 
types are small (axiom (WS) to be precise) is inherited by sheaf models: we show this using 
the axiom of multiple choice. In fact, we suspect that something of this sort is unavoidable 
and one has to go beyond CZF proper to show that its validity is inherited by sheaf models. 
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2 Preliminaries 

2.1 Review of Algebraic Set Theory 

In this section we recall the main features of our approach to Algebraic Set 
Theory from [HIE]- 

We will always assume that our ambient category £ is a positive Heyting 
category. That means that £ is 

(i) Cartesian, i.e., it has finite limits. 

(ii) regular, i.e., morphisms factor in a stable fashion as a cover followed by a 
monomorphism |3 

(iii) positive, i.e., it has finite sums, which are disjoint and stable. 

(iv) Heyting, i.e., for any morphism f:Y >X the induced pullback functor 

/*: Sub(A) >Sub(T) has a right adjoint V/. 

This means that £ is rich enough to interpret first-order intuitionistic logic. Such 
a category £ will be called a category with small maps, if it comes equipped with 
a class of maps S satisfying a list of axioms. To formulate these, we use the 
notion of a covering square. 



Definition 2.1 A diagram in £ of the form 




6 Recall that a map /: B — > A is a cover, if the only sub-object of A through which it factors, 
is the maximal one; and that / is a regular epimorphism if it is the coequalizer of its kernel 
pair. These two classes coincide in regular categories (see 1221 Proposition Al.3.4]). 
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is called a quasi- pullback, when the canonical map D >B Xa C is a cover. If 

p is also a cover, the diagram will be called a covering square. When / and g 
fit into a covering square as shown, we say that / covers g, or that g is covered 

by f- 

Definition 2.2 A class of maps in £ satisfying the following axioms (Al-9) 
will be called a class of small maps: 

(Al) (Pullback stability) In any pullback square 

D > B 

9 f 



where / G S, also g G S. 

(A2) (Descent) If in a pullback square as above p is a cover and g G 5, then 
also / G S. 

(A3) (Sums) Whenever X \Y and X' >Y' belong to S, so does X + 

X' >Y + Y'. 

(A4) (Finiteness) The maps >l, I >1 and 1 + 1 >1 belong to S. 

(A5) (Composition) S is closed under composition. 
(A6) (Quotients) In a commuting triangle 



Z »Y 




if / is a cover and h belongs to 5, then so does g. 

(A7) (Collection) Any two arrows p: Y >X and /: X >A where p is a cover 

and / belongs to S fit into a covering square 

Z > Y — X 

9 f 

B »A, 

where g belongs to S. 
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(A8) (Heyting) For any morphism /: Y >X belonging to S, the right adjoint 

to pullback 

V/:Sub(y) >Sub(A) 

sends small monos to small monos. 
(A9) (Diagonals) All diagonals Ax-X >X x X belong to S. 

For further discussion of these axioms we refer to [5] . 

A pair {£ , S) in which S is a class of small maps in £ will be called a category 
with small maps. In such categories with small maps, objects A will be called 
small, if the unique map from A to the terminal object is small. A subobject 
A C X will be called a small subobject if A is a small object. If any of its 
representing monomorphisms to: A — > X is small, they all are and in this case 
the subobject will be called bounded. 

Remark 2.3 In the sequel we will often implicitly use that categories with 
small maps are stable under slicing. By this we mean that for any category 
with small maps (£,<S) and object X in £, the pair (£/X,S/X), with S/X 
being defined by 

f£S/X&X x feS, 

is again a category with small maps (here Ex is the forgetful functor £/X — > 
£ sending an object p: A — > X in £/X to A and morphisms to themselves). 
Moreover, any of the further axioms for classes of small maps to be introduced 
below are stable under slicing, in the sense that their validity in the slice over 1 
implies their validity in every slice. 

Remark 2.4 A very useful feature of categories of small maps, and one we will 
frequently exploit, is that they satisfy an internal form of bounded separation. 
A precise statement is the following: if 4>{x) is a formula in the internal logic 
of £ with free variable x <E X, all whose basic predicates are interpreted as 
bounded subobjects (note that this includes all equalities, by (A9)), and which 
contains existential and universal quantifications 3^ and V/ along small maps / 
only, then 

A = {x e X : <f>(x)} C X 

defines a bounded subobject of A. In particular, smallness of X implies small- 
ness of A. 

Definition 2.5 A category with small maps (£,S) will be called a predicative 
category with small maps, if the following axioms hold: 

(IIE) All morphisms / € S are exponentiable. 

(WE) For all /: X >Y e S, the W-type W } associated to / exists. 



8 



(NE) £ has a natural numbers object N. 
(NS) Moreover, N ► 1 E S. 

(Representability) There is a small map ir: E >U (the "universal small 

map") such that any /: Y >X G S fits into a diagram of the form 

Y« B >E 

f 

X M A > U, 

where the left hand square is covering and the right hand square is a 
pullback. 

(Bounded exactness) For any equivalence relation 

R) >X x X 

given by a small mono, a stable quotient X/R exists in £. 

(For a detailed discussion of these axioms we refer again to [5]; W-types and 
the axiom (WE) will also be discussed in Section 2.3 below.) 

In predicative categories with small maps one can derive the existence of a 
power class functor, classifying small subobjects: 

Definition 2.6 By a D -indexed family of subobjects of C, we mean a subobject 
JJCCxfl. It will be called a D-indexed family of small subobjects, whenever 
the composite 

RCC x D >D 

belongs to S. If it exists, the power class object V S X is the classifying object 
for the families of small subobjects of X. This means that it comes equipped 
with a V s X-indexed family of small subobjects of X, denoted by 6jC X x V S X 
(or simply e, whenever X is understood), with the property that for any Y- 
indexed family of small subobjects of X, R C X x Y say, there exists a unique 
map p: Y >V S X such that the square 

R > e x 



X x Y > X x V S X 

id xp 

is a pullback. 

Proposition 2.7 [9l Corollary 6.11] In a predicative category with small maps 
all power class objects exist. 
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Moreover, one can show that the assignment X ^ V S X is functorial and that 
this functor has an initial algebra. 

Theorem 2.8 [9, Theorem 7.4] In a predicative category with small maps the 
V s -functor has an initial algebra. 

The importance of this result resides in the fact that this initial algebra can be 
used to model a weak intuitionistic set theory: if V is the initial algebra and 
E: V — >• V S V is the inverse of the 'Ps-algebra map on V (which is an isomorphism, 
since V is an initial algebra), then one can define a binary predicate e on V by 
setting 

xey E(y), 

where GyC V x V S V derives from the power class structure on V S V. The 
resulting structure (V, e) models a weak intuitionistic set theory, which we have 
called RST (for rudimentary set theory), consisting of the following axioms: 

Extensionality: Vx ( xea ■<-> xeb ) — > a = b. 

Empty set: 3xVy^yex. 

Pairing: 3x Vy ( yex <-> y = aV y = b). 

Union: 3x Vy ( yex <-> 3zea yez). 

Set induction: Vr (Vyea; <j>{y) — > 4>(x)) — > Vx<f>(x). 

Bounded separation: 3x\/y ( yex yea A 4>(y) ), for any bounded formula 4> 
in which a does not occur. 

Strong collection: Vxea 3y (f>(x, y) — > 3b B(xea, yeb) <fi, where B(xea, yeb) </> ab- 
breviates 

Vrrea 3yeb <fi A Vye& 3xea 4>. 
Infinity: 3a ( 3x xea ) A ( Vxea 3yea xey ) . 

In fact, as shown in [9], the initial Ps-algebras in predicative categories with 
small maps form a complete semantics for the set theory RST. To obtain com- 
plete semantics for better known intuitionistic set theories, like IZF and CZF, 
one needs further requirements on the class of small maps S. For example, the 
set theory IZF is obtained from RST by adding the axioms 

Full separation: 3a; Vy ( yex «-> yea A <p(y) ), for any formula <p in which a does 
not occur. 

Power set: 3a; Vy ( yea; <-> y C a ), where y C a abbreviates Vz (zey —> zea). 

And to obtain a sound and complete semantics for IZF one requires of ones 
predicative category of small maps that it satisfies: 
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(M) All monomorphisms belong to S. 

(PS) For any map /: Y >X G S, the power class object Vf(f) >X in S/X 

belongs to S. 

The set theory CZF, introduced by Aczel in [I], is obtained by adding to RST 
a weakening of the power set axiom called subset collection: 

Subset collection: ElcVz (Vxea 3yeb <fi(x, y, z) — ?> 3decB(xea,yed) <p(x,y, z)). 

For a suitable categorical analogue, see Section 2.3 below. 

For the sake of completeness we also list the following two axioms, saying 
that certain II-types and W-types are small. (The first therefore corresponds to 
the exponentiation axiom in set theory; we will say more about the second in 
Section 2.2 below.) 

(IIS) For any map /: Y > X e S, a functor 

U f :S/Y^£/X 
right adjoint to pullback exists and preserves morphisms in S. 

(WS) For all /: X >Y 6 S with Y small, the W-type Wf associated to / is 

small. 

2.2 W-types 

In a predicative category with small maps (£,S) the axiom (ITE) holds and 

therefore any small map f:B >A is exponentiable. It therefore induces an 

endofunctor on £, which will be called the polynomial functor Pf associated to 
/. The quickest way to define it is as the following composition: 

C = C/l C/B -^C/A C/l = C. 

In more set-theoretic terms it could be defined as: 

p f (x) = J2x B °. 

Whenever it exists, the initial algebra for the polynomial functor Pf will be 
called the W-type associated to f. 

Intuitively, elements of a W-type are well-founded trees. In the category of 
sets, all W-types exist, and the W-types have as elements well-founded trees, 
with an appropriate labelling of its edges and nodes. What is an appropriate 
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labelling is determined by the branching type /: B >A: nodes should be la- 
belled by elements a £ A, edges by elements b £ B, in such a way that the edges 
into a node labelled by a are uniquely enumerated by / _1 (a). The following 
picture hopefully conveys the idea: 



• a • • • 




This set has the structure of a P/-algebra: when an element a £ A is given, 

together with a map t: B a >Wf, one can build a new element sup i £ Wf, as 

follows. First take a fresh node, label it by a and draw edges into this node, 
one for every b £ B a , labelling them accordingly. Then on the edge labelled 
by b £ B a , stick the tree tb. Clearly, this sup operation is a bijective map. 
Moreover, since every tree in the W-type is well-founded, it can be thought of 
as having been generated by a possibly transfinite number of iterations of this 
sup operation. That is precisely what makes this algebra initial. The trees that 
can be thought of as having been used in the generation of a certain element 
w £ Wf are called its subtrees. One could call the trees tb £ Wf the immediate 
subtrees of sup i, and w' £ Wf a subtree of w £ Wf if it is an immediate subtree, 
or an immediate subtree of an immediate subtree, or. . . , etc. Note that with 
this use of the word subtree, a tree is never a subtree of itself (so proper subtree 
might have been a better terminology). 

We recall that there are two axioms concerning W-types: 

(WE) For all /: X >Y £ S, the W-typc Wf associated to / exists. 

(WS) Moreover, if Y is small, also Wf is small. 



Maybe it is not too late to point out the following fact, which explains why 
these axioms play no essential role in the impredicative setting: 

Theorem 2.9 Let (£,S) be a category with small maps satisfying (NS) and 
(M). 

1. If S satisfies (PE) 7 then it also satisfies (WE). 

2. If S satisfies (PS) 7 then it also satisfies (WS). 

Proof. Note that in a category with small maps satisfying (M) and (PE) the 
object V s (l) is a subobject classifier. Therefore the first result can be shown 
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along the lines of Chapter 3 in [23]. For showing the second result, one simply 
copies the argument why toposes with nno have all W-types from [29]. □ 

In the sequel we will need the following result. We will write Vl[X for the 
object of small inhabited subobjects of X: 

V+X = {Ae V S X :3xeX(xe A)}. 

Theorem 2.10 For any small map f:B —> A in a predicative category with 
small maps (£,S), the endofunctors on £ defined by 

$ = P f o V s and $ = P f o Vf 

have initial algebras. 

Remark 2.11 Before we sketch the proof of Theorem l2.10[ it might be good to 
explain the intuitive meaning of these initial algebras. In fact, they are variations 
on the W-types explained above: they are also classes of well-founded trees, but 
the conditions on the labellings of the nodes and edges are slightly different. 
It is still the case that nodes are labelled by elements a G A and edges with 
elements b € B, in such a way that if b 6 B decorates a certain edge, then 
f(b) decorates the node it points to. But whereas in a W-type, every node in 
a well-founded tree labelled with a £ A has for every b G / _1 (a) precisely one 
edge into it labelled with b, in the initial algebras for $ there are set-many, and 
possibly none, and in the initial algebra for ^ there are set-many, but at least 
one. 

Proof. The proof of Theorem 12. 101 is a variation on that of Theorem 7.4 in [9 
and therefore we will only sketch the argument. 

Fix a universal small map ir: E — > U, and write 

S = {(a E A,u £ U,<f>: E u ^ B a )}. 

Let JC be the W-type in £ associated to the map g fitting into the pullback 
square 

R >E 

g tt 



An element k € JC is therefore of the form sup( a u ^t, where (a, u,<j)) G S 
is the label of the root of k and t: E u — > JC is the function that assigns to 
every element e G E u the tree that is attached to the root of k with the edge 
labelled with e. Define the following equivalence relation on JC by recursion: 
sup (o> „^)t ~ sup^^-jt', if a = a' and 
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for all e G E u there is an e' £ E u i such that </>(e) = 4>'{e') and i(e) ~ 
i'(e'), and for all e' £ E u i there is an e G i? u such that 0(e) = 
4>'{e') and t(e) ~ t'(e'). 

(The existence of this relation ~ can be justified using the methods of [5] or [5]. 
See Theorem 7.4 in |5J, for instance.) The equivalence relation is bounded (one 
proves this by induction) and its quotient is the initial algebra for $. 

The initial algebra for is constructed in the same way, but with S defined as 

S = {{a 6 A, u e U, 4>: E u — ¥ B a ) : <f) is a cover}. 

□ 

2.3 Fullness 

In order to express the subset collection axiom, introduced by Peter Aczel in Q] , 
in diagrammatic terms, it is helpful to consider an axiom which is equivalent 
to it called fullness (see [3]). In the language of set theory one can formulate 
fullness using the notion of a multi-valued section: a multi-valued section (or 

mvs) of a function (j>: b >a is a multi- valued function s from a to b such that 

4>s = id a (as relations). Identifying s with its image, this is the same as a subset 

p of b such that p C b >a is surjective. For us, fullness states that for any 

such cj) there is a small family of mvss such that any mvs contains one in this 
family. Written out formally: 

Fullness: 3z(z C mvs(0) A Va;emvs(</>) 3cez (c C x)). 

Here, mvs(^) is an abbreviation for the class of all multi-valued sections of a 
function cj): b >a, i.e., subsets p of b such that \/xea3yep<t>(y) = x. 

In order to reformulate this diagrammatically, we say that a multi-valued 

section (mvs) for a small map 4>: B >A, over some object X, is a subobject 

P C B such that the composite P >A is a small cover. (Smallness of this 

map is equivalent to P being a bounded subobject of B.) We write 

mvsx(0) 

for the set of all mvss of a map </>. This set obviously inherits the structure of 

a partial order from Sub(-B). Note that any morphism f:Y >X induces an 

order-preserving map 

/* : mvsx (4>) > mvsy (/*</>), 

obtained by pulling back along /. To avoid overburdening the notation, we will 
frequently talk about the map (f> over Y , when we actually mean the map f*4> 
over y, the map / always being understood. 

The categorical fullness axiom now reads: 
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(F) For any <p: B >A G S over some X with A >X e S, there is a cover 

q: X' >X and a map y: Y >X' belonging to S, together with an mvs 

P of (j) over Y, with the following "generic" property: if z: Z \X' is any 

map and Q any mvs of <f> over Z, then there is a map k: U >Y and a 

cover I: U >Z with yk = zl such that k*P < l*Q as mvss of (/> over U. 



It is easy to see that in a set-theoretic context fullness is a consequence of 
the powerset axiom (because then the collection of all multi- valued sections of a 
map <p:b — >• a forms a set) and implies the exponentiation axiom (because if z is 
a set of muss of the projection p:ax6->a such that any mvs is refined by one 
is this set, then the set of functions from a to b can be constructed from z by 
selecting the univalued elements, i.e., those elements that are really functions). 
Showing that in a categorical context (F) follows from (PS) and implies (ITS) 
is not much harder and we will therefore not write out a formal proof. 

In the sequel we will use the following two lemmas concerning the fullness 
axiom: 

Lemma 2.12 Suppose we have the following diagram 




in which the square is a quasi-pullback and f\ and fa are small. When P is a 

"generic" mvs for a map 4>: B >A over X living over Y\ ("generic" as in the 

statement of the fullness axiom), then f3* P is also a generic mvs for <p, living 
over Y2 . 



Proof. A simple diagram chase. 



□ 



Lemma 2.13 Suppose we are given a diagram of the form 

B »B 

A W A 



Xn—^X, 
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in which both squares are covering and all the vertical arrows are small. If a 
generic mvs for ip exists over Xq, then also a generic mvs for cj> exists over X . 

Proof. This was Lemma 6.23 in [5]. □ 



2.4 Axiom of multiple choice 

The axiom of multiple choice was introduced by Moerdijk and Palmgren in [29] . 
Their motivation was to have a choice principle which is implied by the existence 
of enough projectives ("the presentation axiom" in Aczel's terminology) and is 
stable under taking sheaves (unlike the existence of enough projectives). We 
will use it in Section 4.4 to show that the axiom (WS) is stable under taking 
sheaves. 

One can give a succinct formulation of the axiom of multiple choice using 
the notion of a collection span (see [5J Definition 6.14] )0 

Definition 2.14 A span (g,h) in £ 

C^D^B 

is called a collection span, when, in the internal logic, it holds that for any 

map /: E >D C covering some fibre of g, there is a fibre D c > of g and a map 

p:D c i >E such that fp is a cover over B. A collection span is £/A will be 

called a collection span over A. 

Diagrammatically, we can express this by asking that for any map e: E >C 

and any epi F > E Xp D there is a diagram of the form 




C < E' » E > C 



where the middle square is a covering square, involving the given map F > Dxc 

E, while the other two squares are pullbacks. 

(AMC) (Axiom of multiple choice) For any small map f:Y >X, there is a 

7 The way we formulate the Axiom of Multiple Choice here is slightly different from how it 
was stated in 1291 . Both formulations are equivalent, however; see |14| . 



16 



cover q: A >X and a diagram 



D ^q*Y »Y 

a q'f f 
C » A » X, 

in which the right square is a pullback and the left square a covering square 
in which all maps are small and in which (g, h) is a collection span over 



In the internal logic (AMC) is often applied in the following form: 

Lemma 2.15 In a predicative category with small maps in which (AMC) 

holds, the following principle holds in the internal logic: any small map f: B >A 

between small objects fits into a covering square 

q 

D >B 

9 / 

C^A 

in which all maps and objects are small and (g,q) is a collection span over A. 
Proof. This is proved exactly as Proposition 4.6 in [29]. □ 



The following result was proved in as well. Recall from [31 0] that the 
existence of many inductively defined sets within CZF can be guaranteed, in a 
predicatively acceptable way, by extending CZF with Aczel's Regular Extension 
Axiom. 

Proposition 2.16 If(£,S) is a predicative category with small maps satisfying 
the axioms (AMC), (IIS) and (WS), then Aczel's Regular Extension Axiom 
holds in the initial V s -algebra in this category. 

In addition, we will need: 

Proposition 2.17 Let (£,S) be a predicative category with small maps. If S 
satisfies the axioms (AMC) and (IIS), then it satisfies the axiom (F) as well. 

Proof. We argue internally and use Lemma 12.151 So suppose that (AMC) 
holds and /: B — > A is a small map between small objects. We need to hnd a 
small collection of mvss {P y : y G Y} such that any mvs of / is refined by one 
in this family. 
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We apply Lemma 12.151 to A — > 1 to obtain a covering square of the form 



C- 



such that for any cover p:E-^D c we find a d £ C and a map t: D d — > E such 
that pt is a cover over A. Let Y be the collection of all pairs (c, s) with c in C 
and s a map Z? c — > such that fs = h c , and let P y be the image of the map 
s: D c —> B. Then P y is an mvs, because the h c are epi, and Y is small, because 
(nsj holds. 



Now suppose n: Q — >• 2? is any mono such that fn:Q — > B 
a c e C and pull back /n along ft, c to obtain a cover q: E - 



> A is a cover. Pick 
D r , as in: 




It follows that there exists an element d € C and a map g: D c i — > E such that 
qg is a cover over A. Set s = npg and y = (d , s). Then P y = Im(g) is contained 
in Q. □ 



2.5 Main results 

After all these definitions, we can formulate our main result. Let A be either 
{(F)}, or {(AMC), (ITS), (WS)}, or {(M), (PS)}. 

Theorem 2.18 Let (£,S) be a predicative category with small maps for which 
all the axioms in A hold and let (C, Cov) be an internal Grothendieck site in £, 
such that the codomain map C\ — > Co is small and a presentation for the topology 
exists. Then in the category of internal sheaves Shg(C) one can identify a class 
of maps making it into a predicative category with small maps for which the 
axioms in A holds as well. 

In combination with Theorem 12.81 this result can be used to prove the exis- 
tence of sheaf models of various constructive set theories: 

Corollary 2.19 Suppose that (£,S) is a predicative category with small maps 
satisfying the axiom (F) and suppose that (C, Cov) is an internal Grothendieck 
site in £ , such that the codomain map C\ — > Co is small and a presentation for 
the topology exists. Then the initial V s -algebra in Shg(C) exists and is a model 
o/CZF. //, moreover, 
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1. the axioms (AMC) and (WS) hold in E, then the initial V s -algebra in 
Shf(C) also models Aczel's Regular Extension Axiom. 

2. the axioms (M) and (PS) hold in £ , then the initial V s -algebra in Shg(C) 
is a model of IZF. 

3 Presheaves 

In this section we show that predicative categories with small maps are closed 
under presheaves. More precisely, we show that if {£, S) is a predicative category 
with small maps and C is an internal category in £ , then inside the category 
Pshg (C) of internal presheaves one can identify a class of maps such that Pshs (C) 
becomes a predicative category with small maps. Our argument proceeds in two 
steps. First, we need to identify a suitable class of maps in a category of internal 
presheaves. We take what we will call the pointwise small maps of presheaves. 
To prove that these pointwise small maps satisfy axioms (Al-9), we need to 
assume that the codomain map of C is small (note that the same assumption 
was made in |34) ) . Subsequently, we show that the validity in the category with 
small maps {£, S) of any of the axioms introduced in the previous section implies 
its validity in any category of internal presheaves over (£ , S). To avoid repeating 
the convoluted expression "the validity of axiom (X) in a predicative category 
with small maps implies its validity in any category of internal presheaves over 
it", we will write "(X) is inherited by presheaf models" or "(X) is stable under 
presheaf extensions" to express this. 

The main result of this section is that the fullness axiom (F) is stable under 
presheaf extensions. Most of the other stability results in this section are not 
really new and can in one form or another already be found in [24, 28, 29, 151134). 
Nevertheless, for several reasons, we have decided to include their proofs here. 
First of all, none of the references we mentioned uses conditions on the ambient 
category which are exactly the same as ours (in particular, we assume only 
bounded exactness) . Secondly, these papers use different definitions of the class 
of small maps in presheaves, which we will compare in Section 3.2 below. And, 
thirdly, including them will make our presentation self-contained. 

3.1 Pointwise small maps in presheaves 

Throughout this section, we work in a predicative category with small maps 
(£,<S) in which we are given an internal category C, whose codomain map 

cod: C\ >Cq 

is small. Here we have written Cq for the object of objects of C and C\ for its 
object of arrows. In addition, we will write Pshg(C) for the category of internal 
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presheaves, and ir* for the forgetful functor: 

7r*:Psh £ (C) >£/C a . 

In the sequel, we will use capital letters for presheaves and morphisms of 
presheaves, and lower case letters for objects and morphisms in C. 

We will also employ the following piece of notation. For any map of presheaves 
F: Y — > X and element x G X(a), we set 

Y X M : = { (/ G d, y G F(dom/)) : cod(/) = a, F(y) = x-f}. 

(The capital letter M stands for the maximal sieve on b: for this reason, this 
piece of notation is consistent with the one to be introduced in Section 4.4.) 
Occasionally, we will regard Y]jf as a presheaf: in that case, its fibre at b G Co 
is 

Y x M (b) = { (/: b -> a G Ci, y G Y{b)) : F b (y) = x-f}, 
and the restriction of an element (/, y) G Y^r (b) along g: c — > b is given by 

(f,y) -9 = (fg,yg)- 

A map of presheaves F: Y — > X will be called pointwise small, if tt*F belongs 
to S/Cq in S/Cq. Note that for any such pointwise small map of presheaves and 
for any x G X(a) with a G Co the object Y X M will be small. This is an immediate 
consequence of the fact that the codomain map is assumed to be small. 

Theorem 3.1 The pointwise small maps make Pshf(C) into a category with 
small maps. 

Proof. Observe that finite limits, images and sums of presheaves are computed 
"pointwise", that is, as in £/Cq. The universal quantification of A C Y along 
F: Y >X is given by the following formula: for any a G Co, 

V F (A)(a) = {xeX(a):V(f,y)eY x M (yeA)} (1) 

This shows that Psli£(C) is a positive Heyting category. To complete the proof, 
we need to check that the pointwise small maps in presheaves satisfy axioms 
(Al-9). We postpone the proof of the collection axiom (A7) (it will be Proposi- 
tion [3121) • The remaining axioms follow easily, as all we need to do is verify them 
pointwise. For verifying axiom (A8), one observes that the universal quantifier 
in (JlJ ranges over a small object. □ 

For most of the axioms that we introduced in Section 2, it is relatively 
straightforward to check that they are inherited by presheaf models. The ex- 
ceptions are the representability, collection and fullness axioms: verifying these 
requires an alternative characterisation of the small maps in presheaves and 
they will therefore be discussed in a separate section. 
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Proposition 3.2 The following axioms are inherited by presheaf models: (M) , 
bounded exactness, (NE) and (NS), as well as (IIE). (IIS) and (PS). 

Proof. The monomorphisms in presheaves are precisely those maps which 
are pointwise monic and therefore the axiom (M) will be inherited by presheaf 
models. Similarly, presheaf models inherit bounded exactness, because quotients 
of equivalence relations are computed pointwise. Since the natural numbers 
objects in presheaves has that of the base category £ in every fibre, both (NE) 
and (NS) are inherited by presheaf models. 

Finally, consider the following diagram in presheaves, in which F is small: 

B 

G 

Y—^X. 

The object P = II f{G) over an element x G X(a) is given by the formula: 
P x : = { s £ Htf t y)£Y M Gl {y) '■ s i s natural}. 

This shows that (IIE) is inherited by presheaf extensions. It also shows that 
(IIS) is inherited, because the formula 

V(/, y) £ Y x M (b) Vg:c^b (s(f, y) ■ g = s(fg, y ■ g)) 

expressing the naturality of s is bounded. 

To see that (PS) is inherited, we first need a description of the T^-functor in 
the category of internal presheaves. This was first given by Gambino in [18] 
and works as follows. If X is a presheaf and yc is the representable presheaf on 
c £ Co, then 

V s (X)(c) = {4CycxI:iisa small subpresheaf } , 

with restriction along /:d^conan element A 6 V s (X)(c) defined by 

(A ■ /)(e) = {(<?: e d, x G X(e)) : (fg, x) g A}. 

The membership relation Ex<^= X x V S X is defined on an object c £ C by: for 
all x £ X(c) and A £ V s (X)(c), 

x £ X A (id c ,x) £ A. 

This shows that the axiom (PS) is inherited, because the formula 

V(/:6 ->• c,x) £ AMg:a -> b[(fg,x- g) £ A] 

expressing that A is a subpresheaf is bounded. □ 
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Theorem 3.3 The axioms (WE) and (WS) are inherited by presheaf exten- 
sions. 

Proof. For this proof we need to recall the construction of polynomial functors 
and W- types in presheaves from [35]. For a morphism of presheaves F: Y — >• X 
and a presheaf Z, the value of 

p F (z) = zYi 

on an object a of Cq is given by 

P F (Z)(a) = {(x£X(a),t:Y x M ^Z)}, 

where t is supposed to be a morphism of presheaves. The restriction of an 
element (x, t) along a map /: b — > a is given by (x ■ f, f*t), where 

(tt)(g,y) = t(fg,y). 
The presheaf morphism F induces a map 

* E E E *w 

aeC x£X(a) aeC 

in £ whose fibre over x £ X(a) is and which is therefore small. The W-type 
in presheaves will be constructed from the W-type V associated to cj> in £. 

A typical element v £ V is a tree of the form 

v = sup x t 

where x is an element of some X(a) and t is a function Y]jf — > V. For any such 
v, one defines its root p(v) to be a. If one writes V(a) for the set of trees v 
such that p(v) — a, the object V will carry the structure of a presheaf, with the 
restriction of an element v £ V(a) along a map /: b >a given by 

v ■ f = sup x . f f*t. 

The W-type associated to F in presheaves is obtained by selecting the right trees 
from V, the right trees being those all whose subtrees are (in the terminology 
of [28] ) composable and natural. A tree v — sup x (t) is called composable if for 
all (f,y)£Y x M , 

p(t(f,y)) = dom{f). 

A tree v = s\xp x {t) is natural, if it is composable and for any (/, y) £ Y x 4 (a) 
and any g:b — > a, we have 

t(f,y) ■ 9 = t(fg,y g) 
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(so t is actually a natural transformation). A tree will be called hereditarily 
natural, if all its subtrees (including the tree itself) are natural. 

In |281 Lemma 5.5] it was shown that for any hereditarily natural tree v rooted 
in a and map f:b—> a in C, the tree v ■ f is also hereditarily natural. So when 
W(a) C V(a) is the collection of hereditarily natural trees rooted in a, W is a 
subpresheaf of V. 

A proof that W is the W-type for F can be found in the sources mentioned 
above. Presently, the crucial point is that the construction can be imitated 
in our setting, so that (WE) is stable under presheaves. The same applies to 
(WS), essentially because W was obtained from V using bounded separation 
(in this connection it is essential that the object of all subtrees of a particular 
tree v is small, see |9| Theorem 6.13]). □ 



3.2 Locally small maps in presheaves 

For showing that the representability, collection and fullness axioms are inher- 
ited by presheaf models, we use a different characterisation of the small maps in 
presheaves: we introduce the locally small maps and show that these coincide 
with the pointwise small maps. To define these locally small maps, we have to 
set up some notation. 

Remark 3.4 The functor ir*: Pshf(C) >£/Cq has a left adjoint, which is com- 
puted as follows: to any object (X, ax - X — > Co) and a € Co one associates 

m(X)(a) = {{x eXJ:a^b): a x (x) = 6}, 

which is a presheaf with restriction given by 

0,/) ' 9 = 0,/flO- 
This means that tt*tt[X fits into the pullback square 

ir*ir,X >Ci 

cod 



From this one immediately sees that m preserves smallness. Furthermore, the 
component maps of the counit tt\tt* — > 1 are small covers (they are covers, 
because under it* they become split epis in £/Cq; that they are also small is 
another consequence of the fact that the codomain map is assumed to be small). 

In what follows, natural transformations of the form 

TT\B — > TT\A 
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will play a crucial role and therefore it will be worthwhile to analyse them more 
closely. First, due to the adjunction, they correspond to maps in £ /Co of the 
form 

B -> 7r*7riA 

Such a map is determined by two pieces of data: a map r: B — > A in S, and, for 
any b G B, a morphism Sb'-asib) — > o~A{rb) in C, as depicted in the following 
diagram: 

<jb 



(2) 



(Note that we do not have a at — <jb in general, so that it is best to consider r 
as a map in £.) We will use the expression (r, s) for the map B — > tt*tt\A and 
(r, s)i for the natural transformation tti5 —y mA determined by a diagram as in 
©• ' 

In the following lemma, we collect the important properties of the operation 

(--)!• 

Lemma 3.5 1. Assume r and s are as in diagram (0). Then (r,s)i:iriB — > 
ir\A is a pointwise small map of presheaves iff r: B — » A is small in £. 

2. Assume r: B — > A is a cover and a a'- A — >• Co is an arbitrary map. If we 
set <7b = gat and Sb — ido- B fc for every b G B, then (r, s)\: ttiB — > niA is a 
cover. 

3. If (r,s):B tt*ttiA is a cover and <tb(6) = dom(sf,) for all b G B, then 
also (r, s)\:tt\B — > ir\A is a cover. 

4- If (r, s)r. -k\B — > it\A is a natural transformation determined by a diagram 
as in (0) and we are given a commuting diagram 



V 



-> B 



W 



A 



in £, then these data induce a commuting square of presheaves 



TT,V- 



(h,sp) 



TTUI 



TT\B 
(r,s) t 
-4 7TtA 
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with o\r = ctbP and aw — Moreover, if the original diagram is 

a pullback (resp. a quasi- pullback or a covering square), then so is the 
induced diagram. 

5. If (r, s)\:tt\A —> tt\X and (u,v)r.TT\B —> mX are natural transformations 
with the same codomain and for every x £ X and every pair (a, b) 6 
A Xx B with x — ra — ub there is a pullback square 



P(a,b) 

a A (a) 



in C, then it\ applied to the object a ax x b- A Xx B —¥ Cq in £/Cq obtained 
by sending (a,b) G A Xx B to fc( 0j 6) is the pullback of (r,s)\ along (u, v)\ 
in Psh e (C): 

ir\(A x x B) > tt\B 



TTlA- 



-^TTlX. 



Proof. By direct inspection. 



□ 



Using the notation we have set up, we can list the two notions of a small 
map of presheaves. 



1. The pointwise definition (as in the previous section): a map F: B > A of 

presheaves is pointwise small, when 7r*-F is a small map in £ /Cq. 

2. The local definition (as in [24]): a map F: B >A of presheaves is locally 

small, when F is covered by a map of the form (r, s)\ in which r is small 
in £. 



We show that these two classes of maps coincide, so that henceforth we can 
use the phrase "small map" without any danger of ambiguity. 

Proposition 3.6 A map is pointwise small iff it is locally small. 

Proof. We have already observed that maps of the form (r, s)\ with r small are 
pointwise small, so all maps covered by one of this form are pointwise small as 
well. This shows that locally small maps are pointwise small. That all pointwise 
small maps are also locally small follows from the next lemma and the fact that 
the counit maps ir\ir*Y — > Y are covers. □ 
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Lemma 3.7 For any pointwise small map F: Z >Y and any map L: ir\B- 

there is a quasi-pullback square of presheaves of the form 



TT\B ■ 



^Z 



with k small in £. 



Proof. Let S be the pullback of F along L and cover S using the counit as in: 

7T\ 7T* S » S > TT\B 



4 7. 



We know the composite along the top is of the form (k,l)\. Because k is the 
composite along the middle of the following diagram and both squares in this 
diagram are pullbacks, k is the composite of two small maps and hence small. 



ir*S > TT*n,B > B 

■k'L 



IT 



□ 



Corollary 3.8 Every pointwise small map is covered by one of the form (r, s)\ 
in which r is small. In fact, every composable pair (G, F) of pointwise small 
maps of presheaves fits into a double covering square of the form 



tt.C- 



-» Z 



(k.i), 

it\B » Y 



TT\A » X, 



in which k and r are small in £. 
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Proof. We have just shown that every pointwise small map is covered by one 
of the form (r, s)\ in which r is small, which is the first statement. The second 
statement follows immediately from this and the previous lemma. □ 



Using this alternative characterisation, we can quickly show that the collec- 
tion axiom is inherited by presheaf models, as promised. 

Proposition 3.9 The collection axiom (A7) is inherited by presheaf models. 



Proof. Let F; M >N be a small map and Q: E >M be a cover. Without 

loss of generality, we may assume that F is of the form (k,l)\ for some small 
map k: X >Y in £ . 

Let n be the map obtained by pullback in £/Co- 

T — »X 



ir*E — -»7r*7r.X. 



Then use collection in £ to obtain a covering square as follows: 



B—^-fT »X 



A- 



-»y. 



Using Lemma l3.5l 4 this leads to a covering square in the category of presheaves 



TT\B ■ > 7TlT > E » mX 

Q 



(d.lnrn)i 

in A ■ 



-» TT\Y, 



thus completing the proof. 



□ 



Proposition 3.10 The representability axiom is inherited by presheaf models. 
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Proof. Let ir: E >U be a universal small map in £ , and define the following 

two objects in £/Cq: 

U' = {(ueU,ce C ,p: E u -> d) :\/eeE u (cod(pe) = c)}, 

au>(u,c,p) = c, 

E' = {(u,c,p,e): (u,c,p) eU',e e E u }, 

(TE'(u,c,p,e) = dom(pe). 



If r: E' — > U' is the obvious projection and s: E' — > C\ is the map sending 
(u, c 7 p, e) to pe, then r and s fit into a commuting square as shown: 



<T E ' 



E' 



dom 
cod 



We claim that the induced map (r, s)\ in the category of presheaves is a universal 
small map. To show this, we need to prove that any small map F can be 
covered by a pullback of (r, s)\. Without loss of generality, we may assume that 
F = (k, l)i for some small map k: X >Y in £ . 

Since tt is a universal small map, there exists a diagram of the form 




cod 



in which the left square is a pullback and the middle one a covering square. 
From this, we obtain a commuting diagram of the form 




cod 
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by putting 



cr w = a Y J, 

n'w = (Tw,(TH'M,Aeefi„.( im -i e ), 

0V = °~xi, 
m'v = (n'hv,mv). 

Together these two commuting diagrams determine a diagram in the category 
of internal presheaves 



Trim 7m 
TTlE' ■<— ITtV — ■ > TTtX 



(h,li) 



(k,l) 



7ri u 1 < — - /Ti w — -» TT'.y, 



in which the left square is a pullback and the right one a covering square (by 
Lemma [3314). □ 



Theorem 3.11 (Assuming C has chosen pullbacks.) The fullness axiom (F) is 
inherited by presheaf models. 

Proof. In view of Lemma [2J~3] and Corollary 13. 8[ we only need to build generic 
mvss for maps of the form [k 1 l)\:-K\B — > tt\A in which k is small, where tt\A 
lies over some object of the form ix\X via a map of the form (r, s)\ in which r 
is small. To construct this generic mvs, we have to apply fullness in £ . For this 
purpose, consider the object 

B = {(b£B,f eC 1 ,g£C 1 ):o- x (rkb)=cod(f),(ri b )g = \d}. 

Here f*lb is understood to be the map fitting, for any b £ B and /: d — > c with 
c = ax(rkb), in the double pullback diagram 

f*a B (b) >a B (b) 

f'h h 
f*o- A (kb) >a A {kb) 

f*Skb S kb 

d >c 

in C. If we write k : B — > A for the map sending (6, /, g) to k(b), then this map 
is small, so we can use fullness in £ to find a cover n:W — > X and a small map 
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too : Zq >W, together with a generic mvs Pq for ko over Zq, as depicted in the 

following diagram. 



P > >Z x x B 



Z x x A 




Z 



ko 



->W——>X 



Now we make a number of definitions: 

Z = { (z G Z , f G Ci) : cod(/) = nmo(zo) and 

(Va g A nmo(zo) ) (36 G S„) (3 5 G d) (z , 6, G P Q }, 
<?z(zo,f) = dom(/), 

K z oJ) = f, 
aw{w) — <Jx{nw). 

In addition, we write m\. Z — > Zo for the obvious (small) projection and m — 
moTOi. Then we obtain the following diagram of presheaves, in which both 
rectangles are pullbacks computed using Lemma 13.51 5: 



n{Z x x B) 

TT](Z X X A) 
TT\Z ■ 



-> TTlW ■ 



-> TT\B 

(k,l), 
-> TT\A 

(r,s), 



(m./i)] 

We wish to define a subpresheaf of tt\(Z Xx B) and prove that it is the generic 
mvs of (k,l)\. We can do this by saying: 



(zq, /, b, h) G P if /i factors through a map g with (zq, 6, /, 5) G Pq. 



The inclusion of P in 7ri(Z xxB) is bounded, because P is defined by a bounded 
formula (using that the codomain map is small) . Furthermore, the induced map 
from P to 7ri(Z Xx A) is a cover by definition of Z. Thus it remains to verify 
genericity. 

To verify this, let E — > ir\W be any map and Q be an mvs of (k,l)\ over E. 
Without loss of generality, we may assume that E is of the form tt\Y (since E 
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can always be covered using the counit). This leads to the following diagram of 
presheaves in which the rectangles are pullbacks: 




Of course, we will assume that the pullbacks are computed using Lemma 13.51 5, 
so that they are ir\(Y Xx B) and ir\(Y Xx A), respectively. It follows that in £ 
we have an mvs Qo for ko over Y, as in 



Qo>- 



^Yx x B 



^B 




Yx x A 



Y 



- >W- 

a 

given by 

(y, b, f, g) € Qo if / = S y and (y, b, g) G Q. 

Therefore, by the genericity of Pq, there is a cover e:U- 
c: U with de = tuqc and 

c*P Q e*Q . 



>Y and a map 
(3) 



Claim: If we put t(u) — (c(u),5 e ( u \), then t(u) G Z for every u G U. Proof: 
Suppose a G A nmoC ( u y We know that there are b G B a ,f,g G C\ such that 
(c(m),6, /, g) G Pa, because Pq —} Zq xx A is surjective, but the question is: 
do we have / = <5 e ( u )? The answer is yes, because if {c(u),b, f,g) G Po, then 
(e(u), b, f, g) G Qo by ([3|). So we have / = 5 e [ u ) by definition of Qo. □ 

It follows that if we put 

au{u): = dom((5 e(u) ) = ov(e(w)) = <r z (t(u)), 
then we have the following diagram of presheaves: 

Tne (m,/i)t 



my 
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To see that this square commutes, we need to chase an element from ir\U along 
the two sides and it suffices to this for an element of the form (u, id). 

(m, n)\TT\t(u, id) = (m, fj,)\(t(u), id) 

= (m, n)](c(u),6 e ( u ),\d) 

= (m c(u),S e ( u )) 

= (de(u),5 e{u) ) 

= (d,5),(e(«),id) 

= (d, 5)\TT\e(u, id). 

Therefore the proof will be finished, once we show that (ir\t)*P C (ir\e)*Q. 

To show this, consider an element (u, b, h) G (ir<t)*P. We then have (t(u), b, h) G 
P, which, by definition of P, means that h factors through a map g such that 
(c(it), 6, S e (u), g) G Po- From ([3]) it follows that (e(tt), 6, § e (u)>9) £ Qo and 
hence (e(u),b,g) G Q, by definition of Qo- Since Q is a presheaf, we also 
have (e(u),b 7 h) 6 Q, whence (u,b,h) £ (me)*Q, as desired. □ 



Remark 3.12 Diagrammatic proofs as the one we just gave are hard to read 
and motivate. One can give a more understandable proof using the internal logic 
of the category of presheaves: for those who are familiar with its intricacies, we 
present such a proof below. 

Theorem 3.13 (Assuming C has chosen finite products.) The fullness axiom 
(F) is inherited by presheaf models. 

Proof. In view of Lemma \2 . 1 31 and Corollary 13.81 we only need to find generic 
mvss for small map (k, 1)\:tt\B —> tt\A, where tt\A is fibred by a small map 
(r, s)r. ir\A — > tt\X over w\X. Then, by replacing C by C/ir\X = J2 x gx C/ a x(x), 
we may even assume that X = 1 = {*} and <Tx{*) = 1. 

Internal universal quantification over mvss of ttiB in the category Pshf(C) 
amounts to £ -internal quantification over certain subpresheaves P of m (B) x 
C{— , c), namely those which are mvss over tt\(A) x C{— , c). Such a subpresheaf 
satisfies 

(Va G A) (Vft: d -»■ <ja(o)) (V/: d c) (3b G P) (3. 9 : d cr B (6)) 
(k(b),lb ° g) = ( a , ^) and (b,g, f) G P C m(P) xC(-c) at d, 

which is equivalent to 

(Va G A) (3b G P) cr A (a) x c -> cr B (6)) 
(fc(6), lb o gr) = (a, 7Ti) and (b,g,Tt2) G P C 7ri(P) x C(— , c) at ^(a) x c, 

or 

(Va G A) (36 G B) (3g: a A (a) xc4 <t b (6)) 
fc(6) = a, lb o g = 7Ti and (6, g, ^2) G P(crA(a) x c). 
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We use fullness in 8 to obtain a small family of subobjects {Qi : i £ 1} which 
form a generic family of muss for 

{(b G B, c G C , g- cr A (kb) x c ->• cr B (6)) : l b o g = m} -> A: (b,c,g) H> fc(6). 

From these Qi we now construct an internal small family of small presheaves 
of tt\(B). Such a family is generated by subpresheaves of ir\(B) x C(— ,c) for 
varying c £ Co- For any such c G Co, we take the presheaves 

Qi^^) = {(b € B,gh,W2h): g:aA(kb) x c—t aB(b),h:d—)- aA(kb) x c 



provided i and c make the map Q\ —> it\(A) x C(— , c) surjective. 
Now we show these are generic. Take cq G C and P a mvs over cq, as in 



This P satisfies (j4} for cq, so there is a Qi contained in 

{(b G B,co,g:a A (kb) x c -> ctb(&)) : (b,g,Tr 2 ) 6 P, h ° = tti}. 

We claim that the map Q,[ — >• 7Ti(A) x C(— , Co) is surjective, and to show this 
it suffices to prove that elements of the form (a, m: <J A (a) x cq — > cq, ir 2 : x 
Co — > cta(ci)) are hit by this map. Since Qi is a mvs, we know that there are 
(6, c, g) € with fc(6) = a and h ° 9 = fti- Since Qi C P, we have c = Co and 
hence (b,g,ir 2 ) £ Q| Co) and ((fc, Z)i x id)(-, c )(6, g, 7r 2 ) = (a,7Ti,7r 2 ). 

So it remains to check q\ c °^ C P. But if (b,gh,Tt2h) £ Qi° (d) for some 
maps h: d aA(kb) x c and g:aA(kb) x c — » (t_b(&) with (6, co,<?) G Qi, then 
(6, g, 7r 2 ) G P(<TA{kb) x c) and hence (b,gh,ir 2 h) = (b,g,ir 2 ) ■ h G P(<i). □ 



4 Sheaves 

In this section we continue to work in the setting of a predicative category with 
small maps {£ , 5) together with an internal category C in £ whose codomain 
map is small. To define a category of internal sheaves, we have to assume that 
the category C comes equipped with a Grothendieck topology, so as to become 
a Grothendieck site. There are different formulations of the notion of a site, all 
essentially equivalent f |23] provides an excellent discussion of this point), but 
for our purposes we find the following ( "sifted" ) formulation the most useful. 



and (b,c,g) G Qi}, 



p y 




+ 7T|(B) xC(- c ) 



■K\{A) x C(-,c ). 
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Definition 4.1 Let C be an internal category whose codomain map in small. 
A sieve S on an object a 6 Co is a small collection of arrows in C all having 
codomain a and closed under precomposition (i.e., if /: b — > a and g: c — > b are 
arrows in C and / belongs to S, then so does fg). Since we insist that sieves 
are small, there is an object of sieves (a subobject of V S C\). 

We call the set M a of all arrows into a the maximal sieve on a (it is a sieve, 
since we are assuming that the codomain map is small) . If S is a sieve on a and 
/: b — > a is any map in C, we write f*S for the sieve {g: c — > b : fg G 5} on fo. 
In case / belongs to S 1 , we have f*S = Mb- 

A (Grothendieck) topology Cov on C is given by assigning to every object 
a 6 C a collection of sieves Cov(a) such that the following axioms are satisfied: 

(Maximality) The maximal sieve M a belongs to Cov(a); 

(Stability) If /: b — >• a is any map and 5 belongs to Cov(a), then f*S belongs 
to Cov(6); 

(Local character) If S is a sieve on a and R £ Cov(a) is such that for all 
/: b — >• a G i? the sieve /*5 belongs to Cov(fr), then S belongs to Cov(a). 

A pair (C, Cov) consisting of a category C and a topology Cov on it is called 
a s?ie. If a site (C, Cov) has been fixed, we call the sieves belonging to some 
Cov(a) covering sieves. If S belongs to Cov(a) we say that S is a sieve covering 
a, or that a is covered by S. 

Finally, a presentation for a site (C, Cov) is a function BCov which yields, 
for every a 6 Co, a small collection of basic covering sieves BCov(a) such that: 

S e Cov(a) ^3Re BCov(a): RCS. 

A site for which such a presentation exists will be called presentable^ 

Our first goal in this section is prove that any category of internal sheaves 
over a predicative category with small maps (£,S) is a positive Heyting category. 
The proof of this relies on the existence of a sheafification functor (a left adjoint 
to the inclusion of sheaves in presheaves), and since this functor is built by 
taking a quotient, we use the bounded exactness of (£,S). To ensure that the 
equivalence relation by which we quotient is bounded, we will have to assume 
that the site is presentable. Next, we have to identify a class of small maps 
in any category of internal sheaves over (£,S). We will define pointwise small 
and locally small maps of sheaves and we will insist that these should again 
coincide (as happened in presheaves). For this to work out, we again seem to 
need the assumption that the site is presentable; moreover, we will assume that 
the fullness axiom holds in £ (note that similar assumptions were made in |21|). 

8 This is supposed to be reminiscent of Aczel's notion of a set-presentable formal space (see 
[3]). Note that in IZF every site is presentable. 
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So, in effect, we will work in a predicative category with small maps (£,S) 
equipped with a Grothendieck site (C, Cov) such that: 

1. The fullness axiom (F) holds in £ . 

2. The codomain map cod:Ci — > Cq is small. 

3. The site is presentable. 

After we have shown that a category of sheaves can be given the structure 
of a category with small maps, we prove that the validity of any of the axioms 
introduced in Section 2 in (£,S) implies its validity in any category of internal 
sheaves over it (Theorems 4.8-4.11 and Theorem 4.17): we will say that the 
axiom is "inherited by sheaf models" . There is one exception to this, however: 
we will not be able to show that the axiom (WS) is inherited by sheaf models. 
We will discuss the problem and provide a solution based on the axiom of 
multiple choice in Section 4.4 below (see Theorem 14.201 and Theorem 14. 2 1|) . 

The main results of this section are that we establish the stability of fullness 
(F) under sheaves and we correct the treatment of W- types in [55] . In addition, 
we show that the two different notions of a class of small maps that occur in 
the literature coincide in our setting. As far as the basic axioms are concerned, 
their stability can in one form or another already be found in the literature 
(see [231 [5pJ HOI II])- In particular, we should point out that [7] establishes the 
more general result that they are stable under sheaves for a Lawvere-Tierney 
topology. Nevertheless, it is not quite true that our results are a special case 
of theirs, because, to achieve this generality, they work in a setting which has 
full (not just bounded) exactness. In addition, as we already mentioned in the 
introduction, it is not true that the fullness axiom (F) is stable under sheaves 
for a Lawvere-Tierney topology. 

4.1 Sheafification 

Our next theorem shows the existence of a sheafification functor, a Cartesian 
left adjoint to the inclusion of sheaves in presheaves. The proof relies in an 
essential way on the assumption of bounded exactness and on the fact that our 
site is presentable. 

Theorem 4.2 The inclusion 

u:Sh £ (C)> >Psh £ (C) 

has a Cartesian left adjoint i* (a "sheafification functor" ) . 

Proof. We verify that it is possible to imitate the standard construction (see 
[23 Section III.5]). 
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Let P be a presheaf. A pair (R, x) will be called a compatible family on a G 

Co, if R is a covering sieve on a, and ir specifies for every /: b >a G R an 

element x/ G P (6), such that for any g: c >b the equality (xj) ■ g = Xf g holds. 

Because (ITE) holds and sieves are small, by definition, there is an object of 
compatible families. Actually, the compatible families form a presheaf Comp(P) 
with restriction given by 

(R,x)-f = (f*R,x-f), 

where (x ■ f) g = x fg . 

We define an equivalence relation on Comp(P) by declaring two compatible 
families (R, x) and (T, y) on a equivalent, when there is a covering sieve S C 
RDT on a with Xf — yj for all / G S. Since the site is assumed to be presentable, 
this quantification over the (large) collection of covering sieves S on a, can be 
replaced with a quantification over the small collection of basic covering sieves 
on a. Therefore the equivalence relation is bounded and has a quotient P + . 
This object P + is easily seen to carry a presheaf structure in such a way that 
the quotient map Comp(P) — > P+ is a morphism of presheaves. 

First claim: P + is separated. Proof: Suppose two elements [R, x] and [S, y] of 
P + (a) agree on a cover T. Pick representatives (R, x) and (S,y), and define: 

Q = {f:b ya G fin S : x f = y f }. 

Once we show that Q is covering, we are done. But this follows immediately 
from the local character axiom for sites: for any / G T, the sieve f*Q is covering, 
by assumption. 

Second claim: when P is separated, P + is a sheaf. Proof: Let R be a covering 

sieve on a, and let compatible elements pj G P + (b) be given for every /: b >a G 

R. Using the collection axiom, we find for every / G R a family of representatives 
(R(f' l>> , x^' 1 ^) of pf, with the variable i running through some inhabited and 
small index set //. Therefore 

S = {fog:feR,i€l f ,g€R^} 
is small; in fact, it is a covering sieve, by local character. 

We now prove that for any two triples (/ G R, i G If,g G R^'^) and (/' G 

R,i' G I f >,g' G R( f ''^) with fg = f'g', we must have x g fA = x ( g f , ' . Since the 
elements pf are assumed to be compatible, the equality 

[tfW), itM] ■g = Pfg = Pfw - [&t'S\xW>] ■ g' 

(fi) (f'i 1 ) 

holds. Hence the elements x g and x , ' agree on a covering sieve. Since P 

is assumed to be separated, this implies that the elements x^f' 1 ^ and x g { '' l ^ are 
in fact identical. 
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This argument shows that the definition zj g = x g l> is unambiguous for fg G S, 
and also that (S, z) is a compatible family. As its equivalence class [S, z] is the 
glueing of the family pf we started with, the second claim is proved. 

From the construction it is clear that for any presheaf P the sheaf P ++ has to be 
its sheafification. So we have shown that the construction of the sheafification 
functor carries through in the setting we are working in; that this assignment is 
moreover functorial as well as Cartesian is proved in the usual manner. □ 



Theorem 4.3 Shs(C) is a positive Heyting category. 

Proof. The category of sheaves has finite limits, because these are computed 
pointwise, as in presheaves. Using the following description of images and covers 
in categories of sheaves, one can easily show these categories have to be regular: 

the image of a map F: Y >X of sheaves consists of those x G X(a) that are 

"locally" hit by F, i.e., for which there is a sieve S covering a such that for any 

/: b >a G S there is an element y G Y(b) with F(y) = x ■ f. Therefore a map 

F: Y >X is a cover, if for every x G X{a) there is a sieve S covering a and for 

any /: b —> a G S an element y G Y(b) such that F(y) = x ■ f (such maps are 
also called locally surjective). 

The Heyting structure in sheaves is the same as in presheaves, so the universal 
quantification of A C Y along F: Y >X is given by the formula ([TJ. In- 
deed, from this description it is readily seen that belonging to VV(^4) is a local 
property. 

The sums in sheaves are obtained by sheafifying the sums in presheaves. They 
are still disjoint and stable, because the sheafification functor is Cartesian. □ 



4.2 Small maps in sheaves 

We will now define two classes of maps in the categories of sheaves, those which 
are pointwise small and those which are locally small. Using that (F) holds in 
£ and the fact that the site is presentable, we will then show that they coincide. 
But before we define these two classes of maps, note that we have the following 
diagram of functors: 

S/Co ( = ==» Psh £ (C) 




Sh f (C), 
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where the maps p* and p\ are defined as the composites of 7r and i via the 
diagram. So p* is the forgetful functor, p\ is defined as 

P\X = l*TT\X, 

and they are adjoint. It follows immediately from the maximality axiom for 
sites that the components of the counit p\p* > \ are covers. 

One final remark before we give the definitions. We have seen that any pair 
of maps (r, s) in £ making 



B — Ci — — > C 

dom 



cod 



commute determines a map (r, s)r.ir\B — > tt\B of presheaves. Therefore it also 
determines a map i*(r, s)\: p\B — > p\ A of sheaves, but note that now not all maps 
p\B — > pi A will be of this form, in contrast to what happened in the presheaf 
case. 

Finally, the two classes of maps are defined as: 



1. The pointwise definition: a morphism F: B yA of sheaves is pointwise 

small, when p*F is a small map in £/Co. 

2. The local definition (as in [24]): a morphism F: B >A of sheaves is 

locally small in case it is covered by a map of the form i*(r, s)\ where r is 
a small map in £ . 



That these two classes of maps coincide will follow from the next two proposi- 
tions, both whose proofs use the fullness axiom. 



Proposition 4.4 The sheafification functor i* preserves pointwise smallness: 
if F is a (pointwise) small map of presheaves, then i*F is a pointwise small 
map of sheaves. 



Proof. To prove the proposition, it suffices to show that the (— ) + -construction 

preserves smallness. So let F:P >Q be a (pointwise) small morphism of 

presheaves and q be an element of Q + {a) 1 i.e. q — [R,x] where R is a sieve 
and (xf)f£R is a family of compatible elements. The fibre of F + over q con- 
sists of equivalence classes of all those compatible families (S, y) on a such that 
(S, F(y)) and (R, q) are equivalent (by F{y) we of course mean the family given 
by F(y)f — F(yf)). Because every such equivalence class is represented by a 
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compatible family (S, y) where S is a basic covering sieve contained in R and 
F(yf) = Xf for all / G S, the fibre of F over q is covered by the object: 



E IP" 1 ^/)- 

56BCov(a),SC_R feS 



It follows from the fullness axiom in £ that this object is small (actually, the 
exponentiation axiom (IIS) would suffice for this purpose) and then it follows 
from the quotient axiom (A6) that the fibre of F over q is small as well. □ 



Proposition 4.5 The pointwise small maps in sheaves are closed under covered 
maps: if 

X >A 




is a covering square of sheaves (i.e., P and the induced map X — > Y x b A are 
locally surjective) and F is pointwise small, then also G is pointwise small. 



Proof. To make the proof more perspicuous, we will split the argument in two: 
first we show closure of pointwise small maps under quotients and then under 
descent. 

So suppose first that we have a commuting triangle of sheaves 




with F pointwise small and G locally surjective. Fix an element b £ B(c). The 
fullness axiom in £ implies that for any basic covering sieve S € BCov(c) there 
is a small generic family P b of mvss of the obvious (small) projection map 

pf : Y b s = {(/: d^ceS,ye Y(dj) : F d (y) = b ■ /} > S, 

such that any mvs of this map is refined by one in P b (recall that an mvs of pjj 
would be a subobject L C Y b s such that the composite L C Y b s — > S is a small 
cover). Strictly speaking, the fullness axiom says that for every S <E BCov(c) 
such a generic mvs exists, not necessarily as a function of S. This does follow, 
however, using the collection axiom: for this axiom tells us that there is a small 
family {Pi : i £ I b } of such mvss for every S. So we can set P b s = {J ieI s Pi to 

get a generic mvs of p b as a function of S. 
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Call an element L G P b s compatible after G, if for any pair of elements (/: d — > 
c, y) and (/': d' — > c, y') in L we have 

Vg: e -> d, g': e -> d' ( /<? = /V -g = G d , (y r ) ■ g' ). 

Note that there is a map 

g: ^ {Le Pj? : L compatible after G } -> i? c _1 (6), 

SGBCov(c) 

which one obtains by sending (5, L) to the glueing of the elements {G d {y) ■ (/: d — > 
c,y)eL}mI. The domain of this map g is small, so the desired result will fol- 
low, once we show that this map is a cover. For this we use the local surjectivity 
of G. 

Local surjectivity of G means that for every x E X(c) in the fibre over b e B(c), 
there is a basic covering sieve S € BCov(c) such that 

Vf:d^ceS3yeY(d):G d (y) = x-f. 

But Gd(y) — x ■ f implies that F d {y) = b ■ /, so 

{(f:d^c,y&Y(d)):G d (y)=x-f} 

is an mvs of pf and therefore it is refined by an element of P h s . Since this 
clement must be compatible after G, we have shown that q is a cover. 

Second, suppose we have a pullback square of sheaves 



f G 
Y B, 

where F is pointwisc small and P and Q are locally surjective. Again, for any 
b G P(c) and basic covering sieve 5 of c, let be the map 

pf : Y b s = {(/: d -> c G S, y G F(d)) : P d (y) = 6 • /} > 5, 

as above. Furthermore, let mvs(p b ) be the object of mvss of p§ and set 

y '( c ) = E E mvs (pf)> 

6eS(c) SGBCov(c) 

X'(c) = ^ {fee J] F^iy): k compatible after Q}, 

(6,s,L)ey(e) (f:d^c, v )eL 

where we call k G II(/:d-»-c y)ei ^ r d~ 1 (y) compatible after Q, if for any (/:d — > 
c, y) and (/': d' — > c, j/') in L we have 

V 5 : e -> d, 5 ': e -> d' E C (fg = f'g' Qd(k (ftV) ) ■ g = Qd>(k {f > , v >)) ■ g')- 
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This leads to a commuting square in £/Cq 



X'{c)-^A{c) 



F' 



Y'(c)-^B(c), 



in which P' and F' are the obvious projections and Q' sends (6, S, L, k) to the 
glueing of {Qd{k(f, y )) : (/, y) G L}. The square is a pullback in which the map 
P' is a cover (this uses the collection axiom) and F' is small, so that G c is a 
small map by descent (A2) in £/Cq. This completes the proof. □ 



Theorem 4.6 The pointwise small maps and locally small maps of sheaves 
coincide. 



Proof. That all locally small maps of sheaves are also pointwise small follows 
from the previous two propositions. To prove that all pointwise small maps are 
also locally small we use that the pointwise and locally small maps coincide in 
presheaves. 

So consider a pointwise small map F: B >A of sheaves. Since i*F is a point- 
wise small map of presheaves, there is a small map of presheaves (fc, l)\ with k 
small in £ such that 

tt\X > i*B 



(k,i). 



my ■ 



i»F 

-> i*A 



is a covering square in presheaves. Applying sheafification i* and using that 
= 1, we obtain a diagram of the desired form. □ 



Corollary 4.7 Any pointwise small map is covered by one of the form i*(r, s)\ 
with r small in £. In fact, every composable pair (G, F) of pointwise small maps 
of sheaves fits into a double covering square of the form 



P\C- 



i'(k,l). 



P\B 



i* (r,s)\ 



-» z 



p\A » X, 



in which k and r are small in £. 
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Proof. Immediate from the previous theorem and the corresponding fact for 
presheaves ( Corollary 13.81) . □ 



Henceforth we can therefore use the term "small map" without danger of 
ambiguity. The first thing to do now is to show that the small maps in sheaves 
really satisfy the axioms for a class of small maps. 

Theorem 4.8 The small maps in sheaves satisfy axioms (Al-9). 

Proof. Again, we postpone the proof of the collection axiom (A7) (it will be 
Theorem 14. 101) . Because limits in sheaves are computed as in presheaves, (Al) 
and (A9) are inherited from presheaves. Colimits in sheaves are computed 
by sheafifying the result in presheaves, hence the axioms (A3) and (A4) follow 
from Proposition ^. 41 That pointwise small maps are closed under covered maps 
was Proposition 14.51 this disposes of (A2) and (A6). Pointwise small maps 
are closed under composition, so (A5) holds as well. Finally, since universal 
quantification in sheaves is computed as in presheaves, the axiom (A8) holds 
in sheaves, because it holds in presheaves. □ 



Theorem 4.9 The following axioms are inherited by sheaf models: bounded 
exactness, representability, (NE), (NS), (TIE), (ITS), (M) and (PS). 

Proof. Bounded exactness is inherited by sheaf models, since one can shcafify 
the quotient in presheaves. Representability is inherited for the same reason: 
one sheafifies the universal small maps in presheaves. Also the natural num- 
bers object in sheaves is obtained by sheafifying the natural numbers object in 
presheaves, so (NE) and (NS) are inherited by sheaf models. Since IT-types 
in presheaves are computed as in sheaves and (IIE) and (IIS) are inherited 
by presheaf models, they will also be inherited by sheaf models. Finally, since 
monos in sheaves are pointwise, (M) is inherited as well. 

The 7-Vfunctor in sheaves is obtained by quotienting the 7-Vfunctor in presheaves 
(see Proposition 13. 2p by the following equivalence relation (basically, bisimula- 
tion understood as in sheaves): if A, A' C yc x X, then A <~ A' if for all 
(/: b — > c, x) £ A(c), the sieve 

{g:a^b: (fg,x-g) £ A' } 

covers b, and for all (/': b' — > c, x') £ A'(c) the sieve 

{g'-.a'^b 1 : (f'g' ,x' ■ g') £ A} 

covers b'. 

One easily verifies that this defines an equivalence relation in presheaves; more- 
over, it is bounded, since the site is assumed to be presentable. Its quotient 
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P has the structure of a sheaf (as we have seen several times, to construct the 
glueing one uses the collection axiom to select small collections of representa- 
tives from each equivalence class). One defines the relation <ExQ X x P on an 
object c € C by putting for any x e X{c) and A 6 P s (X)(c), 

x E [A] -^=> the sieve {/: d — ¥ c : (/, x ■ /) G A} covers c. 

A straightforward verification establishes that this is indeed the power class ob- 
ject of X in sheaves. Hence the axiom (PS) is inherited by sheaf models. □ 

In the coming two subsections we will discuss the collection and fullness 
axioms and W-types in sheaf categories. 



4.3 Collection and fullness in sheaves 

Theorem 4.10 The collection axiom (A7) is inherited by sheaf models. 



Proof. Let F:M >N be small map and E: Y >M be a cover in sheaves 

(i.e. E is locally surjective). Without loss of generality we may assume that F 
is of the form i*(k, l)r. p\B — > pi A. 

If the map Q: X — >• ir\B of presheaves is obtained by pulling back the map i*E 
along the component of the unit 1 — >• i*i* at tt\B as in 



X 



->i*Y 



Q 

TT\B ■ 



-» i*p\B = i*i*ir\B, 



then this map Q also has to be locally surjective. This means that for the 
following object in £ 

C = {(beB,S e Cov(c)) : a B {b) = c and 

(V/: d -> c e S) (3x G X{d)) (Q(x) - (b, /))}, 

the obvious projection so: C — > B is a cover. Therefore we can apply the collec- 
tion axiom in £ to obtain a covering square of the form: 



V ■ 



U ■ 



(5) 



with I small in £. We wish to apply the collection axiom again. For this purpose, 
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define the following two objects in £ : 



V = {(veVJ eC): ii Sl (v) = (b,S), then feS}, 
W = { (v € V, f: d -> c, x 6 X(d)): if s x (d) = (&,£), 
then / eS and Qd(x) = (6, /) }, 

and let S3: W —> V and 82- V — > V be the obvious projections. S3 is a cover 
(essentially by definition of C), and the composite I' = ls2 is small. So we can 
apply collection to obtain a covering square in £ 



J- 



V 



(6) 



in which m is small. Writing r — r ri and s = S0S1S2S3S4, we obtain a com- 
muting square 




with every j £ J determining an element b 6 B, a sieve S" on erg (6), an arrow 
f E S and an element x 6 X(dom /) such that Q(x) = (b, f) G tt<B. If for such 
an element j £ J we put p.j{j) = dom(/), ^ = /, rij = h° f and for every i E I 
we define crj(i) = cr^ri), then we obtain a square of presheaves: 



(*,t)i 

TT\J > Tl\B 



(m,n)i 



ml ■ 



-> mi. 



To see that it commutes, we chase an element around the two sides of the 
diagram and it suffices to do that for an element of the form (j, id). So 

7T<r(m,n)](j, id) = mr(mj,lb ° /) = (rmj,k ° /), 

and (M)l(s,t)i(i, id) = (k,l)\(sjj) = (ksj,l b of). 

We claim that sheafifying the square gives a covering square. Since r is a cover 
and pi preserves these, this means that we have to show that the map from 
7n J to the pullback of the above square is locally surjective. Lemma 13.51 4 
tells us that we may assume that the pullback is of the form ir\(I Xa B) with 

c/xab(*)^) = a B(b)- The induced map K:tt\J >tt\(I Xa B) sends (J,g) to 

{{mj, sj), f o g), where / is the element in C\ determined by j € J as above. To 
show that this map is locally surjective, it suffices to prove that every element 
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((i,b), id) G tt\(I X-a B) is locally hit by K. The element i g J determines an 
element r\i G U, and since |5} is a covering square, we find a v & V with 
Iv = r\i and sqSiv = b, hence a covering sieve S on pB(b)- Moreover, since 
© is a covering square, we find for every / 6 S an element j G J such that 
m(j) = i and s(j) = 6. Then K(j, id) = ((i, 6), /) = ((i, 6), id) • /, which proves 
that K is locally surjective. 

To complete the proof, we need to show that (s, t)i;fj >mfl factors through 

Q.X >ttiB. There is a map (p,q):J >tt*X which sends every j G J to 

the x G X(dom /) that it determines. Its transpose (p, q)< sends (j, id) to 
x e X which in turn is sent by Q to Q{x) = (sj, /) = (s, id). Therefore 

(s,«)i = Q(p,?)i- " D 



Theorem 4.11 (Assuming C has chosen pullbacks.) The fullness axiom (F) is 
inherited by sheaf models. 



Proof. In view of Lemma 12.131 and Corollary 14.71 it will suffice to show that 

there exists a generic mvs for any map of the form i*(k, n)\: p\B > p\A, living 

over some object of the form p\X via some map i*(r, p)\: p\A >p\X 1 with k 

and r small. 

We first construct the generic mvs P. To this end, define: 

So = {(a ei,a:(i4c,S G BCov(a*cr J 4(a))) : ax(ra) = c} 
M = {(a G A,a:d -> c, S G BCov(a*a A {a)), P G S) : <J X {ra) = c} 
B Q = {(b G B,a:d^ c,S G BCov(a*a A (kb)),P G 5, 7 G d : 
ax{rkb) = c, a* Kb o 7 = /?} 

(In the definition of So and Mo we have used that any pair consisting of a map 
a: d — > c G C and element a £ A with o~x(ra) = c determines a pullback diagram 

a*a A {a) > a A (a) 

OC* Pa 



-)■ c 



in C; in the definition of Bq we have used that any pair consisting of a map 
a: d — > c G C and element b G -B with o~x(rkb) — c determines a double pullback 
diagram 

a*a B (b) ► <r B {b) 



*a A (kb) > a A (kb) 



a pkb 



Pkb 



-4- C 
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in C.) One easily checks that all the projections in the chain 
B Q > M > So > A > X 

are small. 

For the construction of P, we first build a generic mvs for Sq — 

means we have a cover n: W >X and a small map mo'. Z\ > 

a generic mvs Pi for So >A over Z\, as in the diagram 



— >A over X. This 
-W, together with 



^S 



A 1 



Zi 



where the rectangles are understood to be pullbacks. Next, we pull Bq 
Sq back along Pi — !> So and obtain the diagram 



M -> 



Bi 



Mi 



^Bo 



+ So 



Pi - 

Then we build a generic mvs for B\ — > Mi over Zi. This we obtain over an 

object Z2 via a small map Z2 >W and a cover W' >Zi. Without loss of 

generality, we may assume that the latter map W — > Zi is the identity. (Proof: 

apply the collection axiom to the small map Z\ >W and the cover W' \Z\ 

to obtain a small map S >R covering the morphism Z\ >W . Lemma 12.121 

tells us that there lives a generic mvs for So >A over S as well. By another 

application of Lemma 12.121 there lives a generic mvs for Bi — > Mi over T, if 

T — > S is the pullback of Z >W' along the map S >W.) So we may assume 

there is a small map mi: Z2 >Zi, such that over Z2 there is a generic mvs P2 

for i?i — > Mi, as in the following diagram 



P?> 



- B2 



' M 2 > Mi 



^M 
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where all the rectangles are supposed to be pullbacks. Fo convenience, write 
t = nrriomi. 

We make some definitions. First of all, let 

Z = {{z 2 G Z 2 , S: d -> c) : a x (t(z 2 )) = c and 

(Va G A (Z2) ) (35 G BCov(5Va(o)) (mi(«),a,*,S) G Pi}. 

Furthermore, we write m 2 :Z — > Z 2 for the obvious projection and put m = 
tyiqtyi\tyl 2 . Finally, we let P3 be the pullback of P 2 along m 2 . 

We wish to construct a diagram of presheaves of the form: 
P> ► n\(Z x x B) > ir\B 

(fe,K), 

TTl(Z X X A) > TT\A 

(r,p)\ 

TT\Z > 1T\W > 7TlX, 

(m,/i)i ' TT\7l 

which we can do by putting az{z 2 , 5) = cod(<5) and ^( Z2 ,S) = Note that irm is 
a cover and (m, /x) t is small. In addition, P is defined by saying that an element 
(z G Z,b G B,r):c ->■ d) emfZxx P)(c) belongs to P(c) if 

there is a sieve £ G BCov(^*ov[(fc6)), a map /3 G S and a map 7 G Ci 
such that (z, 6, fi z , 5, /3, 7) belongs to P3 and 77 factors through 7. 

By construction, the map P >ir\(Z x x A) is locally surjective. By sheafifying 

the whole diagram, we therefore obtain an mvs i*P for i*(k, k)i over p\Z in the 
category of sheaves. The remainder of the proof will show it is generic. 

To that purpose, let V > p\W be a map of sheaves and Q be an mvs for i* (k, k)\ 

over V. Let Y be the pullback in presheaves of V along the map tt\W — > p\W 
and cover Y using the counit tt\tt*Y — > Y. Writing Y — ir*Y, this means we 
have a commuting square of presheaves 

ir\Y ir\W 



V > P\W, 

in which the vertical arrows are locally surjective and the top arrow is of the 
form (I, A)]. Finally, let Q be the pullback of Q along tt\Y — > V. This means we 
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have the following diagram of presheaves: 

Q> > n\(Y x x B) >tt\B 

TT\(Y x x A) > n\A 

(r,p)i 

iriY >tt<W Uril, ' 

(LX), ■ 7r.n • ' 

where the rectangles are pullbacks, computed, as usual, using Lemma 13.51 5 
(so <T Y x x A(y,a) = Kj°a{o) and <J Y x x B{y,b) = \* y (J B (b)). The map Q -)• 
w\(Y Xx A) is locally surjective, and therefore 

Qi = {{y,a,\ V7 S e BCov(A*cr A (a))): 

(V/3 G 5) (3b G B a ) (37 G d) (y, 6, 7 ) G Q and A; K6 o 7 = (3 } 
= {(y,a,\y,S eBCov(\;a A (a))): 

(V/3 G S) (3b G B„) (3 7 G Ci) (y, b, 7 ) G Q and (6, A„, 5, /3, 7 )eB } 

is an mws of So — ► A over 1". By the genericity of Pi this implies the existence 
of a map Ui:f7i — > Zi and a cover w\:Ui — > V such that mo^i = lu>i an d 
v*-Pi < w^Qi as mvss of 5*0 — > Ao over {Ji. Note that this means that 

(v 1 (u 1 ),a,a,S) e Pi =^ a = X Wl(ui} . (7) 

Next, define the subobject Q2 Q v*Bi by saying for any element (ui G Ui,b G 
B,S G BCov(A; i(ui) a^(fc6)),/3 G 5, 7 Gd) G wffli: 

(tti, 6, 5", /3, 7) G Q 2 (wiui, 6, 7) G Q(dom( 7 )). 

It follows from and the definition of Qi that Q2 is a small mvs of £?i — > Mi 

over C7i. Therefore there is a map i> 2 : U >Zi and a cover W2- U >U% such 

that V1W2 = tti\V2 and V2P2 < w^Q2- Note that (jTJ) implies that «2 factors 
through mi: Z — > Z2 via a map v.U — > Z given by u(u) = (^(u), A U!lW2 ( tt )). 

If we put w = W1W2, then Iw = lw\W2 = moviwi — mamivi = momxmiv = 
rav. Since for each u G U, az(vu) = dom(\ wu ) = (Ty(wu), we may put <Ju(u) — 
az(vu) = ay(wu) and then ir\w and tt\v define maps tt\U — > tt\Y and tt\U — > n\Z , 
respectively, such that (I, \)\Tt\w = (m, ft)imt). Because ir\w is a cover, the proof 
will be finished, once we show that (tt\v)*P < (%\w)*Q. 

To show this, consider an element (u G U,b G B , ij: c ^ d G C) £ w<(U Xx B)(c) 
for which we have (u,b,Tj) G (m?;)*P(c). This means that (vu,b,rj) G -P(c) and 
hence that there is a sieve S G BCov(/i* u ovi(fc&)), a map /3 E S and a map 
7: e — >• d G Ci such that (int, 6, fi VUl S, /3, 7) G P3 and 77 factors through 7. The 
former means that (V2U, b, ju, vu , S, /3, 7) G P2 and since V2P2 < W2Q2, it follows 
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that (w2U,b,S,/3, r y) £ Q 2 - By definition this means that (wu, 6,7) 6 Q(e). 
Since Q is a presheaf, also (wu,b,r]) £ Q(c) and hence (u,b,r]) £ (tt\w)*Q(c). 
This completes the proof. □ 



Remark 4.12 Again, one can also prove this result using the internal logic of 
categories of sheaves. Also to illustrate its power, we give one such proof here. 

Theorem 4.13 (Assuming C has chosen finite products.) The fullness axiom 
(F) is inherited by sheaf models. 

Proof. In view of Lemma and Corollary 13. 81 we only need to build generic 
muss for maps of the form i*(k,l)\: p\B — > p\A in which k is small, where p\A 
lies over some object of the form p\X via a map of the form i*(r, s)\ in which r 
is small. Again, by replacing C by C/p\(X), we may assume that X = 1 = {*} 
and crx(*) = 1. 

Note that for a fixed c £ Cq an mvs of i*(k,l)\ over i*C(—,c) as in 

P > >p\{B) x i*C(-,c) 

i* ((k,l)\X\d) 

pi(A) x i*C{-,c) 

satisfies 

(Vo G A) (35 G BCov(cr A (a) x c)) 
(V 3 : d -> CT A (a) x c £ 5) (3b £ B) (3/: d -> ct b (6)) (3/i: d -> c) 
(k(b),l b o /) = (a, TTiog),TT 2 og = h and (6, /, /i) G P(d), 

or 

(Vo G A) (35 G BCov(cr A (a)) x c) 
(V 5 : d -> cta(o) x c G 5) (36 G B) (3/: d -> cr B (6)) (8) 
k(b) = a, k o f = 7Ti o g and (6, /, tt 2 o g) £ P(d). 

We first apply fullness in £ to the map 

{(a £ A, c £ C , 5 G BCov(a A (a) x c))} ->■ A: (a, c, 5) ->• a 

to obtain a generic small family of mvss (Qj)jeJ- 
Writing for every j £ J 

Qj := {(a,c,S,g): (a,c,S) £ Qj,g £ S}, 

Qj : = {(a,c,S,g,b,f): (a,c,S) £ Qj,g £ S,b € B,k(b) = a,hf = nig}, 
we have an obvious projection 

Q j ^ Q ' j • 
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Applying fullness and using the collection axiom we obtain generic families 
{Pjjjig^ for these maps as well. (The collection axiom is employed here to 
obtain these generic families as a function of j.) 

For fixed c€C,j € J and i G Ij the object Py determines a subsheaf 

Pjf Cp,(B) xi*C(-, c) 

generated by those elements (6, /, 7T2 o g) for which there is a basic covering sieve 
5 such that (k(b), c, S,g, b, /) g P^. Again, we only take those which are mwss, 
i.e., map in a locally surjective manner to p\(A) x i*C(— ,c). 

Now suppose Co is arbitrary and P C p\(B) x C(— , Co) is an mvs. This means 
that © holds with c = Co- Hence there is a Q,, with 

Qj C {(a,c ,S):{Vg:d^a A (a)xceS)(3beB)(Vf:d^a B (b)) 

k(b) = a, lb o f = m o g and (6, /, 7r 2 ° <?) € P(d) } ^ ' 

and an z G 7j with 

P y C {(a,c ,S,g,b, /) : (6,/, tt 2 o g) g R(d)}. 

It is clear that C P, so it remains to verify that P^ c °' 1 is an mws. 

We check © for c = Co- So take a € A. We want to show that the generator 
(a, 7Ti,7r 2 ) g /Oj(A) x i*C(— ,c ) is locally hit by i*((k,l)\ x id). Because Qj is 
an mvs, there are e g Co and 5 g BCov(cr J 4(a) x e) such that (a,e,S) G 
morever, we must have e = Co, because (O holds. Since P,j is an mvs we know 
that for every g £ S there are 6 g B and / g C\ with (a, Co, 5, g, 6, /) G Py. In 
particular (a, Co, 5, g, 6, /) G Qj, so k(b) — a and h° f = tti °g- By construction 
(&, /j 7T2 5) g p// ' and for this element the equation 

i*((M)i x 7T 2 oj) = (k(b),l b o f,ir 2 o g) = (o,7ri,7r 2 ) -5 

holds. This concludes the proof. □ 



4.4 W-types in sheaves 

In this final subsection, we show that the axiom (WE) is inherited by sheaf 
models. It turns out that the construction of W-types in categories of sheaves 
is considerably more involved than in the presheaf case (in [IU] we showed that 
some of the complications can be avoided if the metatheory includes the axiom 
of choice). We then go on to show that the axiom (WS) is inherited as well, if 
we assume the axiom of multiple choice. 

Remark 4.14 In [28] the authors claimed that W-types in categories of sheaves 
are computed as in presheaves (Proposition 5.7 in loc.cit.) and can therefore be 
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described in the same (relatively easy) way. But, unfortunately, this claim is 
incorrect, as the following counterexample shows. Let F: 1 — > 1 be the identity 
map on the terminal object. The W-type associated to F is the initial object, 
which, in general, is different in categories of presheaves and sheaves. (This was 
noticed by Peter Lumsdaine together with the first author.) 

We fix a small map F: Y — > X of sheaves. If x S X(a) and S is a covering 
sieve on a, then we put 

Y x s ; = {(/: b^aeS,ye Y(b)) : F(y) = *•/}. 

Observe that Y x is small and write tp for the obvious projection 

ir. Y,Y X S ^X x Co Cov. 

(S,x) 

Let '5 = o "P+ and let V be its initial algebra (see Theorem l2.10p . Elements 
v of V are therefore of the form sup^^^t with (a,x, S) G X Xc Cov and 
t: Y x — > V^V. We will think of such an element v as a labelled well-founded 
tree, with a root labelled with (a, x, S). To this root is attached, for every 
UiV) £ Yj? an d w £ i(/)2/)> the tree w with an edge labelled with (/, y). To 
simplify the notation, we will denote by v(f,y) the small collection of all trees 
that are attached to the root of v with an edge that has the label (/, y). 

We now wish to define a presheaf structure on V. We say that a tree oeV 
is rooted at an object a in C, if its root has a label whose first component is a. 
If v = sup( Q x S \t is rooted at a and /: b — > a is a map in C, then we can define 
a tree v ■ f rooted at 6, as follows: 

v ■ f = sup {b!X . fJ * s) f*t, 

with 

(rt)(g,y)=t(fg,y). 
This clearly gives V the structure of a presheaf. Note that 

{v ■ f)(g,y) = v(fg,y). 

Next, we define by transfinite recursion a relation on V: 

v ~ v' if the root of v is labelled with (a, x, S) and the root 

of v 1 with (a', x 1 , 5"), then a = a', x = x' and there 
is a covering sieve R C S (1 S' such that for every 
(/, y) S Y X R we have u(/, y) - v'(f, y). 

Here, the formula v(f,y) ~ v'(f,y) is supposed to mean 
Vm e w(/, y), n G ?/(/, y):m~ n . 



51 



In general, we will write M ~ N for small subobjects M and N of V to mean 

Vra G AT, n G AT : m ~ n. 
In a similar vein, we will write for such a subobject M, 

M ■ f = {m- f: me M}. 

That the relation ~ is indeed definable can be shown by the methods of [8] or 
[5]. By transfinite induction one can show that ~ is symmetric and transitive, 
and compatible with the presheaf structure (v^w^v-f^w-f). 

Next, we define composability and naturality of trees (as we did in the 
presheaf case, see Theorem 13. 3p . 

• A tree v € V whose root is labelled with (a, x, S) is composable, if for any 
(/: b — > a, y) G Y*? and u> G t>(/, y), the tree u> is rooted at b. 

• A tree v G V whose root is labelled with (a, x, S) is natural, if it is com- 
posable and for any (/: b — > a, y) G 3^ and g:c — >■ 6, 

y) ■ 5 ~ v(fg,y g). 

One can show that if u is natural, and v ~ then also w is natural; moreover, 
natural trees are stable under restriction. The same applies to the trees that 
are hereditarily natural (i.e. not only are they themselves natural, but the same 
is true for all their subtrees). 

We shall write W for the object consisting of those trees that are hereditarily 
natural. The relation ~ defines an equivalence on W, for if a tree v = sup( a x g-d 
is natural, then for all (/, y) G Y,f one has v(f,y) ■ id ~ v(f ■ \d,y ■ id), that 
is, v(f,y) ~ v(f,y), and therefore v ~ v. By induction one proves that the 
equivalence relation ~ on W is bounded and hence a quotient exists. We denote 
it by W. It follows from what we have said that the quotient W is a presheaf, 
but more is true: one can actually show that W is a sheaf and, indeed, the 
W-type associated to F in sheaves. 

Lemma 4.15 Let w,w' G W be rooted at a G C. If T is a sieve covering a and 
w ■ f w' ■ f for all f G T , then w ~ w' . In other words, W is separated. 

Proof. If the label of the root of w is of the form (a, x, S) and that of w' is of 
the form (a, x' , S'), then w ■ f ~ w' ■ f implies that x ■ f = x' ■ f for all / G T. 
As X is separated, it follows that x = x'. 

Consider 

R = {g:b^ae(SnS'):V(h,y)eY T M »lw(gh,y)~w'(gh,y)}}. 
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R is a sieve, and the statement of the lemma will follow once we have shown 
that it is covering. 



Fix an element / G T. That w ■ f ~ w' ■ f holds means that there is a 
covering sieve Rf C f*S fl f*S' such that for every (k,y) G Y^j we have 
w(fk,y) = {w ■ f)(k,y) ~ (to' • = w'{fk,y). In other words, i?/ C f*R. 

So i? is a covering sieve by local character. □ 

Lemma 4.16 W is a sheaf. 

Proof. Let S be a covering sieve on a and suppose we have a compatible family 
of elements («T/ G W) / e s- Using the collection axiom, we know that there must 
be a span 

S <- J -> W 

with J small and [u>j] = t/J/^ for all j G J. Every Wj is of form sup( a ^ ,Rj)tj- 
If /j = ff , then ~ Wj' , so a^- = Xj> . Thus the form a compatible family 
and, since X is a sheaf, can be glued together to obtain an element x G X(a). 
We claim that the desired glueing is [w], where w = sup( a x R ^t G V is defined 
by: 

R = {./'-//:./ •/•'/ /'-!• 

t{K y) = \J {tj(g, y) ■ fag = h} 

je.J 

For this to make sense, we first need to show that w G W, i.e., that w is 
hereditarily natural. In order to do this, we prove the following claim. 

Claim. Assume we are given (h,y) G Y^, with h = fjg for some j G J. Then 

w(h,y) ~ Wj(g,y). 

Proof. Since 

w{h,y) = |J {Wj'{g',y) : f r g' = h}, 
j'e.J 

it suffices to show that Wj(g, y) ~ Wj'(g' , y) if ft- = //(/. 

By compatibility of the family (Wf G W)/gs we know that Wj ■ g ~ wy • .g' G 
W(c). This means that there is a covering sieve T C g*Rj n (g')*Rji such that 
for all (fc, 2) G Y^ h , we have (i«j • g)(k, z) ~ (w^ • z). So if fc: d — > c G T, 

then 

Wj{g,y)-k ~ Wj(gk,y-k) 

= {wj ■ g){k,y ■ k) 
~ (wj' ■ g'){k,y ■ k) 
= Wj'{g'k,y-k) 

~ w i'(g',y)-k- 
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Because W is separated (as was shown in Lemma l4.15[) . it follows that Wj (g, y) ~ 
Wj'(g',y). This proves the claim. □ 



Any subtree of w is a subtree of some Wj and therefore natural. Hence we only 
need to prove of w itself that it is composable and natural. Direct inspection 
shows that the tree that we have constructed is composable. For verifying that 
w is also natural, let (h: c —> a,y) G and k: d — > c. Since h G R, there are 
j G J and g G Rj such that h = fjg. Then 

w(h,y) ■ k ~ Wj(g,y) ■ k ~ w 3 (gk,y-k) ~ w(hk,y ■ k), 

by using naturality of Wj and the claim (twice). 

It remains to show that [w] is a glueing of all the w t, i.e., that w • fj ~ uij for 
all j G J. So let j G J. First of all, x ■ fj = Xj, by construction. Secondly, for 
every g: c — >• b G Rj = (Rj D f*R) and y G Y(c) such that F(y) = x ■ fog, we 
have 

■ fj)(9,y) = w{fj9,y) ~ Wj(g,y). 
This completes the proof. □ 



Lemma 4.17 W is a Pp-algebra. 

Proof. We have to describe a natural transformation S: PfW —> W. An 
element of PfW(ci) is a pair (x,t) consisting of an element x G X(a) together 
with a natural transformation G:Y^f a — > W. Using collection, there is a map 

y x m * r+w (io) 

such that [w] = G(y,f), for all (f,y) G Y^ Ia and w G t(f,y). We dehne S X G to 
be 

[sup (a ^ iMo) t]. 

One now needs to check that w is hereditarily natural. And then another ver- 
ification is needed to check that [w] does not depend on the choice of the map 
in (TTU)) . Finally, one needs to check the naturality of S. These verifications are 
all relatively straightforward and similar to some of the earlier calculations, and 
therefore we leave all of them to the reader. □ 



Lemma 4.18 W is the initial Pf -algebra. 

Proof. We will show that S: PpW — > W is monic and that W has no proper 
Pp-subalgebras; it will then follow from Theorem 26 of [8] (or Theorem 6.13 in 
[9]) that W is the W-type of F. 
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We first show that S is monic. So let (x,G), (x',G') £ PfX(cl) be such that 
S X G = S X >G' £ W. It follows that x — x' and that there is a covering sieve S 
on a such that for all (h, y) £ Y^ , we have G(h, y) = G'(h, y). We need to show 
that G = G' . so let (f,y) £ Y^ a be arbitrary. For every g £ f*S, we have: 

G(f, y)-9= G(fg, yg) = G'(fg, y ■ g) = G'(f, y) ■ g. 

Since f*S is covering, it follows that G(f,y) — G'(f,y), as desired. 

The fact that W has no proper Pp-subalgebras is a consequence of the inductive 
properties of V (recall that V is an initial algebra). Let A be a sheaf and Pjr- 
subalgebra of W. We claim that 

B = {v £ V : if v is hereditarily natural, then [«] £ A} 

is a subalgebra of V. Proof: Suppose u is a tree that is hereditarily natural. 
Assume moreover that v = sup( a x s \t and for all (/, y) £ Yj: and w £ t(f, y), 
we know that [w] £ A. Our aim is to show that [v] £ A. 

For the moment fix an element S 1 . Since v ■ f has a root labelled 

by (b,x ■ f,Mb) and (v ■ f){g,y) = v(fg,y) for all (g,y) £ Y^ff , we have that 
[«]■/= S x .fG, where G(g,y) = [v(fg,y)] £ A. Because A is a Pp-subalgebra 
of W this implies that [v] ■ f £ A. Since this holds for every f £ S, while S is a 
covering sieve and A is a subsheaf of W, we obtain that [u] S ^4., as desired. 

We conclude that B — V and hence A = W. This completes the proof. □ 
To wrap up: 

Theorem 4.19 The axiom (WE) is inherited by sheaf models. 

We believe that one has to make additional assumptions on ones predicative 
category with small maps (£,S) to show that the axiom (WS) is inherited by 
sheaf models (the argument above does not establish this, the problem being 
that the initial algebra V will be large, even when the codomain of the map 
F: Y — > X we have computed the W-type of is small). We will now show 
that this problem can be circumvented if we assume that the axiom of multiple 
choice (AMC) holds in £ . It is quite likely that one can also solve this problem 
by using Aczel's Regular Extension Axiom: it implies the axiom (WS) and is 
claimed to be stable under sheaf extensions (but, as far as we are aware, no 
proof of that claim has been published) . 

Theorem 4.20 The axiom (AMC) is inherited by sheaf models. 

Proof. This was proved in Section 10 of □ 
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Theorem 4.21 (Assuming that (AMC) holds in £.) The axiom (WS) is 
inherited by sheaf models. 

Proof. We will continue to use the notation from the proof of the previous 
theorem. So, again, we assume we have a small map F: Y —> X of sheaves. 
Moreover, we let i\> be the map in £ and ^Sf be the endofunctor on £ defined 
above, we let V be its initial algebra and ~ be the symmetric and transitive 
relation we defined on V, and W the W-type associated to F, obtained by 
quotienting the hereditarily natural elements in V by ~. 

Assume that X is a small sheaf. Since (AMC) holds in £ , it is the case that, 
internally in £/Cq, the map ip fits into a covering square as shown 

D > J2(S,x) Y x 

g f 
C — X x Co Cov, 

in which all objects and maps are small in £/Cq and (g,q) is a collection span 
over X x Co Cov. The W-type U = W g in £/C is small in £/C , because we are 
assuming that (WS) holds in £ (and hence also in £/Cq). The idea is to use 
this to show that W is small as well. 

Every element u — sup c s £ U determines an element in (p(u) £ V as follows: 
first compute p(c) = (a, x, S). Then let for every (y, /) 6 the element t(y, f) 
be defined by 

t(y,f) = {( i pos)(d):deq- 1 (y,f)}. 

Then <p(u) = sup( a (so this is an inductive definition). We claim that for 
every hereditarily natural tree v £ W there is an element u £ U such that 
v ~ <p{u). The desired result follows readily from this claim. 

We prove the claim by induction: so let v = sup( a x s \t be a hereditarily natural 
element of V and assume the claim holds for all subtrees of v. Since all subtrees 
of v are hereditarily natural as well, this means that for every (y, f ) £ Y x and 
w £ t(y, /) there is an element u £lA such that ip(u) = w. From the fact that 
(g,q) is a collection span over X Xq Cov, it follows that there is a c £ C with 
p(c) = (a,x,S) together with two functions: first one picking for every d £ D c 
an element r(d) £ t(y,f) (because t(y,f) is non-empty) and a second one pick- 
ing for every d £ D an element s(d) £ U such that <p{s{d)) ~ r(d). It is not 
hard to see that v ~ <p(sup c s), using that v is natural and therefore all elements 
in t(y, f) are equivalent to each other. □ 



This completes the proof of our main result, Theorem 12.181 



56 



5 Sheaf models of constructive set theory 



Our main result Theorem 12.181 in combination with Theorem 12.81 yields the 
existence of sheaf models for CZF and IZF (see Corollary I2.19[) . For the sake 
of completeness and in order to allow a comparison with classical forcing, we 
describe this model in concrete terms. We will not present verifications of the 
correctness of our descriptions, because they could in principle be obtained by 
unwinding the existence proofs, and other descriptions which differ only slightly 
from what we present here can already be found in the literature. 

To construct the initial "P s -algebra in a category of internal presheaves over 
a predicative category with small maps (£,S), let W be the initial algebra of 
the endofunctor <f> = P co d°'P s on £ (see Theorem l2.10p . Elements of w G W are 
therefore of the form sup c t, with c G Co and t a function from {/ G C\ : cod(/) = 
c} to "PsW. We think of such an element w as a well-founded tree, where the 
root is labelled with c and for every v £ t(f), the tree v is connected to the 
root of w with an edge labelled with /. The object W carries the structure of a 
presheaf, with W(c) consisting of trees whose root is labelled with c, and with 
a restriction operation defined by putting for any w = sup c t and /: d — > c, 



The initial "P s -algebra V in the category of presheaves is constructed from 
W by selecting those trees that are hereditarily composable and natural: 

• A tree w = sup c (t) G W is composable, if for any /: d — > c and v G £(/), 
the tree v has a root labelled with d. 

• A tree w — sup c (£) € W is natural, if it is composable and for any f:d^>-c, 
g: e — > d and v 6 t(f), we have v ■ g 6 t(fg). 

The T^-algebra structure, or, equivalently, the membership relation on V, is 
given by the formula (x, sup c i G V) 



The easiest way to prove the correctness of the description we gave is by appeal- 
ing to Theorem 1.1 from (or Theorem 7.3 from [5]). This model was first 
presented in the paper |18] by Gambino, based on unpublished work by Dana 
Scott. 

The initial "P s -algebra in categories of internal sheaves is obtained as a quo- 
tient of this object V. Roughly speaking, we quotient by bisimulation in a way 
which reflects the semantics of a category of sheaves. More precisely, we take V 
as defined above and we write: sup c i ~ sup c t' if for all /: d — > c and v £ t(f), 
the sieve 



w ■ f = sup d t(f o -). 




{g:e^d: 3v' G t'(fg) (v ■ g ~ v' ) } 
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covers d and for all f':d—>c and v' G t'(f'), the sieve 



{g:e->d: 3v G t(f'g) (v' ■ g ~ v ) } 

covers d. On the quotient the membership relation is defined by: 

[v] G [sup c t] the sieve {/: d — > c : 3v' G t(f) ( v ■ g ~ «')} covers c. 

To see that this is correct, one should verify that ~ defines a bounded equiva- 
lence relation and the quotient is a sheaf. Then one proves that it is the initial 
■Ps-algebra by appealing to Theorem 1.1 from [25] (or Theorem 7.3 from [9]). 
The reader who wishes to see more details, should consult [33] . 

Remark 5.1 To see the analogy with classical forcing (as in [26], for example), 
note that any poset P determines a site, by declaring that S covers p whenever 
S is dense below p. In this case, the elements of V are a particular kind of 
names (as they are traditionally called). One could regard composability and 
naturality as saturation properties of names (so that, in effect, we only consider 
nice, saturated names). It is not too hard to show that every name (in the 
usual sense) is equal in a forcing model to such a saturated name, so that in the 
case of classical ZF the models that we have constructed are not different from 
standard forcing models. 
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